Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/brokercap/Bifrost: CVE-2022-39267 #1070

Closed
GoVulnBot opened this issue Oct 19, 2022 · 1 comment
Closed

Comments

@GoVulnBot
Copy link

CVE-2022-39267 references github.com/brokercap/Bifrost, which may be a Go module.

Description:
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no known workarounds.

References:

See doc/triage.md for instructions on how to triage this report.

modules:
  - module: github.com/brokercap/Bifrost
    packages:
      - package: Bifrost
description: "Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB
    to Redis, MongoDB, ClickHouse, MySQL and other services for production environments.
    Versions prior to 1.8.8-release are subject to authentication bypass in the admin
    and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field
    in the request header. This issue has been patched in 1.8.8-release. There are
    no known workarounds. \n"
cves:
  - CVE-2022-39267
references:
  - web: https://github.com/brokercap/Bifrost/security/advisories/GHSA-mxrx-fg8p-5p5j
  - fix: https://github.com/brockercap/Bifrost/pull/201

@tatianab
Copy link
Contributor

Duplicate of #1067

@tatianab tatianab marked this as a duplicate of #1067 Oct 19, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

2 participants