PT-2022-24943 · Kubevela · Kubevela

Wangyikewxgm

·

Published

2022-11-16

·

Updated

2022-12-07

·

CVE-2022-39383

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions KubeVela versions 1.5 through 1.5.7 KubeVela versions 1.6 through 1.6.0
Description KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this issue. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
Recommendations For versions 1.5 through 1.5.7, update to version 1.5.8 or later. For versions 1.6 through 1.6.0, update to version 1.6.1 or later. As a temporary workaround, consider restricting the request address of the warehouse when using Helm Chart as the component delivery method until a patch is available.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2022-39383
GHSA-M5XF-X7Q6-3RM7
GO-2022-1113

Affected Products

Kubevela