Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h4q8-96p6-jcgr

Опубликовано: 19 дек. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5

Описание

ghinstallation returns app JWT in error responses

Impact

In ghinstallation v1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging.

https://github.com/bradleyfalzon/ghinstallation/blob/24e56b3fb7669f209134a01eff731d7e2ef72a5c/transport.go#L172-L174

The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum).

Patches

  • This has already been patched in d24f14f8be70d94129d76026e8b0f4f9170c8c3e, and is available in releases >= v2.0.0.

References

Are there any links users can visit to find out more?

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/bradleyfalzon/ghinstallation

go
Затронутые версииВерсия исправления

< 2.0.0

2.0.0

EPSS

Процентиль: 7%
0.00027
Низкий

5 Medium

CVSS3

Дефекты

CWE-209

Связанные уязвимости

CVSS3: 5
redhat
больше 3 лет назад

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

CVSS3: 5
nvd
около 3 лет назад

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

EPSS

Процентиль: 7%
0.00027
Низкий

5 Medium

CVSS3

Дефекты

CWE-209