Description
Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-6892 | Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds. |
Github GHSA |
GHSA-p6fh-xc6r-g5hw | Brokercap Bifrost subject to authentication bypass when using HTTP basic authentication |
References
History
Tue, 22 Apr 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-22T17:20:25.810Z
Reserved: 2022-09-02T00:00:00.000Z
Link: CVE-2022-39219
Updated: 2024-08-03T12:00:42.533Z
Status : Modified
Published: 2022-09-26T14:15:10.180
Modified: 2024-11-21T07:17:48.827
Link: CVE-2022-39219
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA