Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ggp5-28x4-xcj9

Опубликовано: 09 апр. 2024
Источник: github
Github: Прошло ревью
CVSS3: 4.3

Описание

Minder GetRepositoryByName data leak

Impact

A recent refactoring added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository.

Patches

Patched in #2941

Workarounds

Revert prior to 5c381cf, or roll forward past 2eb94e7

References

N/A

Пакеты

Наименование

github.com/stacklok/minder

go
Затронутые версииВерсия исправления

= 0.0.39

0.0.40

EPSS

Процентиль: 56%
0.00343
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 4.3
nvd
почти 2 года назад

Minder by Stacklok is an open source software supply chain security platform. A refactoring in commit `5c381cf` added the ability to get GitHub repositories registered to a project without specifying a specific provider. Unfortunately, the SQL query for doing so was missing parenthesis, and would select a random repository. This issue is patched in pull request 2941. As a workaround, revert prior to `5c381cf`, or roll forward past `2eb94e7`.

EPSS

Процентиль: 56%
0.00343
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-200