Логотип exploitDog
bind:CVE-2022-39304
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-39304

Количество 3

Количество 3

redhat логотип

CVE-2022-39304

больше 3 лет назад

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

CVSS3: 5
EPSS: Низкий
nvd логотип

CVE-2022-39304

около 3 лет назад

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

CVSS3: 5
EPSS: Низкий
github логотип

GHSA-h4q8-96p6-jcgr

около 3 лет назад

ghinstallation returns app JWT in error responses

CVSS3: 5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2022-39304

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

CVSS3: 5
0%
Низкий
больше 3 лет назад
nvd логотип
CVE-2022-39304

ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT for the App, and was returned back to clients. This token is short lived (10 minute maximum). This issue has been patched and is available in version 2.0.0.

CVSS3: 5
0%
Низкий
около 3 лет назад
github логотип
GHSA-h4q8-96p6-jcgr

ghinstallation returns app JWT in error responses

CVSS3: 5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу