Previously, StreamPipes allowed users to configure custom endpoints from which to install additional pipeline elements.
These endpoints were not properly validated, allowing an attacker to get StreamPipes to send an HTTP GET request to an arbitrary address.
This issue affects Apache StreamPipes: through 0.93.0.
Users are recommended to upgrade to version 0.95.0, which fixes the issue.
No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-9gr7-gh74-qg9x | Apache StreamPipes has possibility of SSRF in pipeline element installation process |
Fri, 13 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
ssvc
|
cvssV3_1
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-09-13T17:04:43.686Z
Reserved: 2024-04-08T12:12:26.266Z
Link: CVE-2024-31979
Updated: 2024-09-13T17:04:43.686Z
Status : Modified
Published: 2024-07-17T09:15:02.907
Modified: 2024-11-21T09:14:16.167
Link: CVE-2024-31979
No data.
OpenCVE Enrichment
No data.
Github GHSA