KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please update the v1.6.1. Users who're using v1.5, please update the v1.5.8. There are no known workarounds for this issue.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2022-11-16T00:00:00
Updated: 2024-08-03T12:07:42.045Z
Reserved: 2022-09-02T00:00:00
Link: CVE-2022-39383
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-11-16T20:15:10.437
Modified: 2024-11-21T07:18:10.910
Link: CVE-2022-39383
Redhat
No data.