PT-2022-10888 · Spinnaker · Spinnaker

Jasonmcintosh

·

Published

2022-01-04

·

Updated

2022-01-18

·

CVE-2021-39143

CVSS v3.1

7.1

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Spinnaker (affected versions not specified)
Description A path traversal vulnerability was discovered in Spinnaker's use of TAR files by AppEngine for deployments. This vulnerability allows an attacker to override files on the container, potentially introducing a Man-in-the-Middle (MITM) type attack vector by replacing libraries or injecting wrapper files. The issue arises because the utility used to extract files locally for deployment does not validate the paths in the deployment, which could lead to system files being overridden.
Recommendations For all affected versions, update Spinnaker as soon as possible. As a temporary workaround for users unable to update, consider disabling Google AppEngine deployments and/or disabling artifacts that provide TARs to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-39143
GHSA-34JX-3VMR-56V8

Affected Products

Spinnaker