PT-2022-16012 · Galaxy · Galaxy
Ghepardo
·
Published
2022-12-06
·
Updated
2022-12-08
·
CVE-2022-23470
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Galaxy versions 22.01 and higher
Description
Galaxy is an open-source platform for data analysis. An arbitrary file read exists due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This issue is mitigated when using Nginx or Apache to serve /static/* contents, instead of Galaxy's internal middleware.
Recommendations
For Galaxy versions 22.01 and higher, users are advised to manually patch their installations using commit
e5e6bda4f. As a temporary workaround, consider using Nginx or Apache to serve /static/* contents instead of Galaxy's internal middleware to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Galaxy