Описание
Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.
Ссылки
- ExploitIssue TrackingThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
- ExploitIssue TrackingThird Party Advisory
- Release NotesThird Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.8.7 (исключая)
cpe:2.3:a:xbifrost:bifrost:*:*:*:*:*:*:*:*
EPSS
Процентиль: 43%
0.00211
Низкий
8.5 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-287
CWE-287
Связанные уязвимости
CVSS3: 8.5
github
больше 3 лет назад
Brokercap Bifrost subject to authentication bypass when using HTTP basic authentication
EPSS
Процентиль: 43%
0.00211
Низкий
8.5 High
CVSS3
6.5 Medium
CVSS3
Дефекты
CWE-287
CWE-287