Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-33987

Опубликовано: 18 июн. 2022
Источник: redhat
CVSS3: 5.3
EPSS Низкий

Описание

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

A flaw was found in the got package for node.js. Requested URLs are not verified and allow open redirection to a local UNIX socket.

Отчет

As got is only a transitive dependency of a development dependency of kiali OpenShift Service Mesh as well as being removed in version 2.2+, this flaw will not be fixed at this time for the openshift-istio-kiali-rhel8-container.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Migration Toolkit for Virtualizationmigration-toolkit-virtualization/mtv-ui-rhel8Fix deferred
.NET 6.0 on Red Hat Enterprise Linuxrh-dotnet60-dotnetAffected
OpenShift Developer Tools and ServicesodoNot affected
OpenShift Service Mesh 2.0servicemesh-grafanaWill not fix
OpenShift Service Mesh 2.1openshift-service-mesh/kiali-rhel8Will not fix
OpenShift Service Mesh 2.1servicemesh-grafanaWill not fix
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/application-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-ui-rhel8Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/grc-ui-api-rhel8Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-601
https://bugzilla.redhat.com/show_bug.cgi?id=2102001nodejs-got: missing verification of requested URLs allows redirects to UNIX sockets

EPSS

Процентиль: 72%
0.00734
Низкий

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 3 лет назад

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

CVSS3: 5.3
nvd
около 3 лет назад

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allows a redirect to a UNIX socket.

CVSS3: 5.3
debian
около 3 лет назад

The got package before 12.1.0 (also fixed in 11.8.5) for Node.js allow ...

CVSS3: 5.3
github
около 3 лет назад

Got allows a redirect to a UNIX socket

rocky
почти 3 года назад

Moderate: nodejs:14 security and bug fix update

EPSS

Процентиль: 72%
0.00734
Низкий

5.3 Medium

CVSS3