Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: netflix
Published: 2020-12-11T02:10:32
Updated: 2024-08-04T10:26:16.028Z
Reserved: 2020-02-19T00:00:00
Link: CVE-2020-9301
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-11T03:15:11.767
Modified: 2024-11-21T05:40:22.980
Link: CVE-2020-9301
Redhat
No data.