Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-m5xf-x7q6-3rm7: List helm chart endpoint of VelaUX APIserver has SSRF vulnerability

Impact

Users using the VelaUX APIServer could be affected by this vulnerability.

When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.

Patches

For users who’re using v1.6, please update the v1.6.1. For users who’re using v1.5, please update the v1.5.8.

References

Fix by: #5000

For more information

If you have any questions or comments about this advisory:

ghsa
#vulnerability#git#ssrf

Impact

Users using the VelaUX APIServer could be affected by this vulnerability.

When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.

Patches

For users who’re using v1.6, please update the v1.6.1.
For users who’re using v1.5, please update the v1.5.8.

References

Fix by: #5000

For more information

If you have any questions or comments about this advisory:

  • Open an issue in KubeVela repo
  • Email us at here

References

  • GHSA-m5xf-x7q6-3rm7
  • https://nvd.nist.gov/vuln/detail/CVE-2022-39383
  • kubevela/kubevela#5000

Related news

CVE-2022-39383: List helm chart endpoint of VelaUX APIserver has SSRF vulnerability

KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please update the v1.6.1. Users who're using v1.5, please update the v1.5.8. There are no known workarounds for this issue.