PT-2022-24956 · Alibaba · Aliyun-Oss-Client

Tu6Ge

·

Published

2022-11-19

·

Updated

2023-07-12

·

CVE-2022-39397

CVSS v3.1

5.6

Medium

VectorAV:P/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions aliyun-oss-client versions prior to 0.8.1
Description The aliyun-oss-client unintentionally divulges the authentication secret. Users of this library will be affected, as the incoming secret will be disclosed unintentionally.
Recommendations For versions prior to 0.8.1, update to version 0.8.1 to resolve the issue. As a temporary workaround, consider restricting access to sensitive information until the update can be applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-39397
GHSA-3W3H-7XGX-GRWC
RUSTSEC-2022-0089

Affected Products

Aliyun-Oss-Client