Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-52477

Опубликовано: 26 июн. 2025
Источник: nvd
CVSS3: 8.6
EPSS Низкий

Описание

Octo-STS is a GitHub App that acts like a Security Token Service (STS) for the GitHub API. Octo-STS versions before v0.5.3 are vulnerable to unauthenticated SSRF by abusing fields in OpenID Connect tokens. Malicious tokens were shown to trigger internal network requests which could reflect error logs with sensitive information. Upgrade to v0.5.3 to resolve this issue. This version includes patch sets to sanitize input and redact logging.

EPSS

Процентиль: 14%
0.00047
Низкий

8.6 High

CVSS3

Дефекты

CWE-918

Связанные уязвимости

CVSS3: 8.6
github
8 месяцев назад

Octo STS Unauthenticated SSRF by abusing fields in OpenID Connect tokens

EPSS

Процентиль: 14%
0.00047
Низкий

8.6 High

CVSS3

Дефекты

CWE-918