PT-2022-16012 · Galaxy · Galaxy

Ghepardo

·

Published

2022-12-06

·

Updated

2022-12-08

·

CVE-2022-23470

CVSS v3.1

8.6

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Galaxy versions 22.01 and higher
Description Galaxy is an open-source platform for data analysis. An arbitrary file read exists due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This issue is mitigated when using Nginx or Apache to serve /static/* contents, instead of Galaxy's internal middleware.
Recommendations For Galaxy versions 22.01 and higher, users are advised to manually patch their installations using commit e5e6bda4f. As a temporary workaround, consider using Nginx or Apache to serve /static/* contents instead of Galaxy's internal middleware to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2022-23470
GHSA-GRJF-2GHX-Q77X

Affected Products

Galaxy