PT-2022-24943 · Kubevela · Kubevela
Wangyikewxgm
·
Published
2022-11-16
·
Updated
2022-12-07
·
CVE-2022-39383
CVSS v3.1
4.9
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
KubeVela versions 1.5 through 1.5.7
KubeVela versions 1.6 through 1.6.0
Description
KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this issue. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
Recommendations
For versions 1.5 through 1.5.7, update to version 1.5.8 or later.
For versions 1.6 through 1.6.0, update to version 1.6.1 or later.
As a temporary workaround, consider restricting the request address of the warehouse when using Helm Chart as the component delivery method until a patch is available.
Exploit
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Kubevela