Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p6fh-xc6r-g5hw

Опубликовано: 27 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.5

Описание

Brokercap Bifrost subject to authentication bypass when using HTTP basic authentication

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

Пакеты

Наименование

github.com/brokercap/Bifrost

go
Затронутые версииВерсия исправления

<= 1.8.6-release

1.8.7-release

EPSS

Процентиль: 44%
0.00211
Низкий

8.5 High

CVSS3

Дефекты

CWE-287
CWE-732

Связанные уязвимости

CVSS3: 8.5
nvd
больше 3 лет назад

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

EPSS

Процентиль: 44%
0.00211
Низкий

8.5 High

CVSS3

Дефекты

CWE-287
CWE-732