HIGHGo →
KubeVela Terraform remote loader DoS via unbounded file read
KubeVela Terraform remote loader DoS via unbounded file read
Affected packages
- github.com/oam-dev/kubevela
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/kubevela/kubevela/security/advisories/GHSA-fmgp-q6jx-gg3x
- https://github.com/kubevela/kubevela/pull/7191
- https://github.com/kubevela/kubevela/pull/7192
- https://github.com/kubevela/kubevela/commit/65dedda40a69cc1eccf4072a4c835e5b9f13334e
- https://github.com/kubevela/kubevela/commit/7a4e59b2958ce1cf031fafbc188d6fafe8fe4d2e
- https://github.com/kubevela/kubevela/commit/f6a64398b5e0065c57c3a0fb6765dd3dc48c749d
- https://github.com/kubevela/kubevela
- https://github.com/kubevela/kubevela/releases/tag/v1.10.9
- https://github.com/kubevela/kubevela/releases/tag/v1.11.0-alpha.4
- https://github.com/kubevela/kubevela/releases/tag/v1.9.14
Structured record: https://osv.dev/vulnerability/GHSA-fmgp-q6jx-gg3x
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta