PT-2022-10888 · Spinnaker · Spinnaker
Jasonmcintosh
·
Published
2022-01-04
·
Updated
2022-01-18
·
CVE-2021-39143
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Spinnaker (affected versions not specified)
Description
A path traversal vulnerability was discovered in Spinnaker's use of TAR files by AppEngine for deployments. This vulnerability allows an attacker to override files on the container, potentially introducing a Man-in-the-Middle (MITM) type attack vector by replacing libraries or injecting wrapper files. The issue arises because the utility used to extract files locally for deployment does not validate the paths in the deployment, which could lead to system files being overridden.
Recommendations
For all affected versions, update Spinnaker as soon as possible.
As a temporary workaround for users unable to update, consider disabling Google AppEngine deployments and/or disabling artifacts that provide TARs to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spinnaker