Description
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-30125 | Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests. |
References
History
No history.
Status: PUBLISHED
Assigner: netflix
Published:
Updated: 2024-08-04T10:26:16.028Z
Reserved: 2020-02-19T00:00:00.000Z
Link: CVE-2020-9301
No data.
Status : Modified
Published: 2020-12-11T03:15:11.767
Modified: 2024-11-21T05:40:22.980
Link: CVE-2020-9301
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD