Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-28110

Опубликовано: 06 мар. 2024
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

A vulnerability was found in cloudevents/sdk-go. This issue involves using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper results in the go-sdk leaking credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, http.DefaultClient is modified with the authenticated transport, causing it to send Authorization tokens to any endpoint it communicates with. This flaw allows an attacker to intercept and abuse these leaked credentials, potentially leading to unauthorized access to sensitive information or executing unauthorized actions on the affected system.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Serverlessopenshift-serverless-clientsNot affected
OpenShift-Pipelines-1.15-RHEL-8openshift-pipelines-clientFixedRHEA-2024:402220.06.2024
Red Hat OpenShift Container Platform 4.15openshift4/ose-consoleFixedRHSA-2024:842531.10.2024
Red Hat OpenShift Container Platform 4.16openshift4/ose-cloud-event-proxy-rhel9FixedRHSA-2024:004027.06.2024
Red Hat OpenShift Container Platform 4.16openshift4/ose-ptp-rhel9-operatorFixedRHSA-2024:004027.06.2024
Red Hat OpenShift Container Platform 4.16openshift4/ose-console-rhel9FixedRHSA-2024:004127.06.2024
RHOSS-1.32-RHEL-8openshift-serverless-1/client-kn-rhel8FixedRHSA-2024:133314.03.2024
RHOSS-1.32-RHEL-8openshift-serverless-1/eventing-apiserver-receive-adapter-rhel8FixedRHSA-2024:133314.03.2024
RHOSS-1.32-RHEL-8openshift-serverless-1/eventing-controller-rhel8FixedRHSA-2024:133314.03.2024
RHOSS-1.32-RHEL-8openshift-serverless-1/eventing-in-memory-channel-controller-rhel8FixedRHSA-2024:133314.03.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-522
https://bugzilla.redhat.com/show_bug.cgi?id=2268372cloudevents/sdk-go: usage of WithRoundTripper to create a Client leaks credentials

EPSS

Процентиль: 49%
0.00661
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

Go SDK for CloudEvents is the official CloudEvents SDK to integrate applications with CloudEvents. Prior to version 2.15.2, using cloudevents.WithRoundTripper to create a cloudevents.Client with an authenticated http.RoundTripper causes the go-sdk to leak credentials to arbitrary endpoints. When the transport is populated with an authenticated transport, then http.DefaultClient is modified with the authenticated transport and will start to send Authorization tokens to any endpoint it is used to contact. Version 2.15.2 patches this issue.

CVSS3: 7.5
msrc
около 2 лет назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
github
больше 2 лет назад

Go SDK for CloudEvents's use of WithRoundTripper to create a Client leaks credentials

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость функции WithRoundTripper() библиотеки для интеграции приложений с облачной инфраструктурой CloudEvents sdk-go, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 49%
0.00661
Низкий

6.5 Medium

CVSS3