Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-1996

Опубликовано: 08 июн. 2022
Источник: redhat
CVSS3: 9.1
EPSS Низкий

Описание

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

A flaw was found in CORS Filter feature from the go-restful package. When a user inputs a domain which is in AllowedDomains, all domains starting with the same pattern are accepted. This issue could allow an attacker to break the CORS policy by allowing any page to make requests and retrieve data on behalf of users.

Отчет

The go-restful package is a transitive dependency which is being pulled with k8s.io/api and not directly being used anywhere in OpenShift Container Platform (OCP), OpenShift Container Storage, OpenShift Data Foundation, OpenShift Do and OpenShift Pipelines, hence these components are marked as 'Will not fix' or even "Not affected".

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServiceshelmAffected
OpenShift Developer Tools and ServicesodoWill not fix
OpenShift Pipelinesopenshift-pipelines-clientNot affected
OpenShift ServerlessCLIAffected
OpenShift Serverlessknative-eventingAffected
OpenShift Service Mesh 2.0servicemeshNot affected
OpenShift Service Mesh 2.1servicemeshNot affected
OpenShift Service Mesh 2.1servicemesh-prometheusNot affected
Red Hat 3scale API Management Platform 23scale-rhel7-operatorAffected
Red Hat Ansible Automation Platform 1.2openshift-clientsWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-639
https://bugzilla.redhat.com/show_bug.cgi?id=2094982go-restful: Authorization Bypass Through User-Controlled Key

EPSS

Процентиль: 76%
0.00963
Низкий

9.1 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
больше 3 лет назад

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVSS3: 9.1
nvd
больше 3 лет назад

Authorization Bypass Through User-Controlled Key in GitHub repository emicklei/go-restful prior to v3.8.0.

CVSS3: 9.1
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 9.1
debian
больше 3 лет назад

Authorization Bypass Through User-Controlled Key in GitHub repository ...

suse-cvrf
больше 3 лет назад

Security update for trivy

EPSS

Процентиль: 76%
0.00963
Низкий

9.1 Critical

CVSS3