Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3pf-j9xx-29g6

Опубликовано: 09 апр. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 4.3

Описание

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches.

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches.

EPSS

Процентиль: 26%
0.0009
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 4.3
nvd
почти 3 года назад

rpk in Redpanda before 23.1.2 mishandles the redpanda.rpc_server_tls field, leading to (for example) situations in which there is a data type mismatch that cannot be automatically fixed by rpk, and instead a user must reconfigure (while a cluster is turned off) in order to have TLS on broker RPC ports. NOTE: the fix was also backported to the 22.2 and 22.3 branches.

EPSS

Процентиль: 26%
0.0009
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-20