PT-2022-3231 · Unknown · Edgexfoundry

Eb-Oss

·

Published

2022-06-14

·

Updated

2024-08-21

·

CVE-2022-31066

CVSS v3.1

5.9

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions EdgeXFoundry versions prior to 2.1.1
Description The /api/v2/config endpoint exposes message bus credentials to local unauthenticated users, bypassing access controls on message bus credentials when running in security-enabled mode. This allows attackers to intercept data or inject fake data into the EdgeX message bus.
Recommendations For EdgeXFoundry versions prior to 2.1.1, upgrade to EdgeXFoundry Kamakura release (2.2.0) or to the June 2022 EdgeXFoundry LTS Jakarta release (2.1.1) to receive a patch. As a temporary workaround, consider restricting access to the /api/v2/config endpoint until a patch is available. For specific go modules, docker containers, and snaps, refer to the GitHub Security Advisory for patch information.

Exploit

Fix

Improper Access Control

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2022-03934
CVE-2022-31066
GHSA-G63H-Q855-VP3Q
GO-2022-0491

Affected Products

Edgexfoundry