PT-2023-12724 · Weave · Weave Gitops

Pjbgf

·

Publicado

2023-01-09

·

Atualizado

2024-08-20

·

CVE-2022-23509

CVSS v3.1

7.3

Alta

VetorAV:A/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Weave GitOps versions prior to v0.12.0
Description The communication between GitOps Run and the local S3 bucket is not encrypted, allowing privileged users or processes to tap the local traffic and gain information permitting access to the S3 bucket. This could result in changes to the bucket content, leading to modifications in the Kubernetes cluster's resources. There are no known workarounds for this issue.
Recommendations For Weave GitOps versions prior to v0.12.0, upgrade to Weave GitOps version >= v0.12.0 released on 08/12/2022. As a temporary workaround, consider restricting access to the local S3 bucket to minimize the risk of exploitation.

Exploit

Correção

Cleartext Transmission of Sensitive Information

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-23509
GHSA-89QM-WCMW-3MGG
GO-2023-1388

Produtos afetados

Weave Gitops