Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c77r-fh37-x2px

Опубликовано: 30 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 5.2
CVSS3: 6.1

Описание

OPA for Windows has an SMB force-authentication vulnerability

A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.

Пакеты

Наименование

github.com/open-policy-agent/opa

go
Затронутые версииВерсия исправления

< 0.68.0

0.68.0

EPSS

Процентиль: 27%
0.00096
Низкий

5.2 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-294

Связанные уязвимости

CVSS3: 6.1
redhat
больше 1 года назад

A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.

CVSS3: 6.1
nvd
больше 1 года назад

A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.

EPSS

Процентиль: 27%
0.00096
Низкий

5.2 Medium

CVSS4

6.1 Medium

CVSS3

Дефекты

CWE-294