Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mgvh-5mj6-fprr

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.

EPSS

Процентиль: 74%
0.00812
Низкий

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 8.8
nvd
около 5 лет назад

Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.

EPSS

Процентиль: 74%
0.00812
Низкий

Дефекты

CWE-502