Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h3qp-hwvr-9xcq

Опубликовано: 26 июн. 2025
Источник: github
Github: Прошло ревью
CVSS3: 8.6

Описание

Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens

Summary

Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information.

Please upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.

Many thanks to @vicevirus for reporting this issue and for assisting with remediation review.

References

Пакеты

Наименование

github.com/octo-sts/app

go
Затронутые версииВерсия исправления

<= 0.5.2

0.5.3

EPSS

Процентиль: 14%
0.00047
Низкий

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
nvd
8 месяцев назад

Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.

EPSS

Процентиль: 14%
0.00047
Низкий

8.6 High

CVSS3

Дефекты

CWE-918