KubeVela VelaUX APIserver has SSRF vulnerability
Moderate severity
GitHub Reviewed
Published
Nov 16, 2022
in
kubevela/kubevela
•
Updated Aug 29, 2023
Package
Affected versions
< 1.5.9
>= 1.6.0-alpha.1, < 1.6.2
Patched versions
1.5.9
1.6.2
Description
Published by the National Vulnerability Database
Nov 16, 2022
Published to the GitHub Advisory Database
Nov 18, 2022
Reviewed
Nov 18, 2022
Last updated
Aug 29, 2023
Impact
Users using the VelaUX APIServer could be affected by this vulnerability.
When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
This issue is patched in 1.5.9 and 1.6.2.
References
Fix by: #5000
For more information
If you have any questions or comments about this advisory:
References