Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements.
These endpoints were not properly validated, allowing an attacker to get StreamPipes to send an HTTP GET request to an arbitrary address.
This issue affects Apache StreamPipes: through 0.93.0.
Users are recommended to upgrade to version 0.95.0, which fixes the issue.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9gr7-gh74-qg9x | Apache StreamPipes has possibility of SSRF in pipeline element installation process |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:04:43.686Z
Reserved: 2024-04-08T12:12:26.266Z
Link: CVE-2024-31979
Updated: 2024-09-13T17:04:43.686Z
Status : Modified
Published: 2024-07-17T09:15:02.907
Modified: 2024-11-21T09:14:16.167
Link: CVE-2024-31979
No data.
OpenCVE Enrichment
No data.
Github GHSA