Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/apache/trafficcontrol/v8: GHSA-vq94-9pfv-ccqr #3358

Open
GoVulnBot opened this issue Dec 23, 2024 · 0 comments

Comments

@GoVulnBot
Copy link

Advisory GHSA-vq94-9pfv-ccqr references a vulnerability in the following Go modules:

Module
github.com/apache/trafficcontrol
github.com/apache/trafficcontrol/v8

Description:
An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "steering" to execute arbitrary SQL against the database by sending a specially-crafted PUT request.

Users are recommended to upgrade to version Apache Traffic Control 8.0.2 if you run an affected version of Traffic Ops.

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/apache/trafficcontrol
      vulnerable_at: 7.0.1+incompatible
    - module: github.com/apache/trafficcontrol/v8
      versions:
        - introduced: 8.0.0
        - fixed: 8.0.2
      vulnerable_at: 8.0.2-rc0
summary: SQL injection in Apache Traffic Control in github.com/apache/trafficcontrol
cves:
    - CVE-2024-45387
ghsas:
    - GHSA-vq94-9pfv-ccqr
references:
    - advisory: https://github.com/advisories/GHSA-vq94-9pfv-ccqr
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2024-45387
    - web: http://www.openwall.com/lists/oss-security/2024/12/23/3
    - web: https://github.com/apache/trafficcontrol/releases/tag/v8.0.2
    - web: https://lists.apache.org/thread/t38nk5n7t8w3pb66z7z4pqfzt4443trr
source:
    id: GHSA-vq94-9pfv-ccqr
    created: 2024-12-23T21:03:28.379904215Z
review_status: UNREVIEWED

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

No branches or pull requests

1 participant