Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m5xf-x7q6-3rm7

Опубликовано: 18 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.9

Описание

KubeVela VelaUX APIserver has SSRF vulnerability

Impact

Users using the VelaUX APIServer could be affected by this vulnerability.

When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.

This issue is patched in 1.5.9 and 1.6.2.

References

Fix by: #5000

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

github.com/oam-dev/kubevela

go
Затронутые версииВерсия исправления

>= 1.6.0-alpha.1, < 1.6.2

1.6.2

Наименование

github.com/oam-dev/kubevela

go
Затронутые версииВерсия исправления

< 1.5.9

1.5.9

EPSS

Процентиль: 42%
0.00196
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 4.9
nvd
около 3 лет назад

KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please update the v1.6.1. Users who're using v1.5, please update the v1.5.8. There are no known workarounds for this issue.

EPSS

Процентиль: 42%
0.00196
Низкий

4.9 Medium

CVSS3

Дефекты

CWE-918