GHSA-9xc9-xq7w-vpcr

Suggest an improvement
Source
https://github.com/advisories/GHSA-9xc9-xq7w-vpcr
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/01/GHSA-9xc9-xq7w-vpcr/GHSA-9xc9-xq7w-vpcr.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-9xc9-xq7w-vpcr
Aliases
Published
2024-01-31T09:30:18Z
Modified
2024-07-08T20:08:14Z
Severity
  • 7.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L CVSS Calculator
  • 7.2 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
Apache ServiceComb Service-Center Server-Side Request Forgery vulnerability
Details

Server-Side Request Forgery (SSRF) vulnerability in Apache ServiceComb Service-Center. Attackers can obtain sensitive server information through specially crafted requests.This issue affects Apache ServiceComb before 2.1.0 (included). Users are recommended to upgrade to version 2.2.0, which fixes the issue.

Database specific
{
    "nvd_published_at": "2024-01-31T09:15:43Z",
    "cwe_ids": [
        "CWE-918"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2024-01-31T22:43:09Z"
}
References

Affected packages

Go / github.com/apache/servicecomb-service-center

Package

Name
github.com/apache/servicecomb-service-center
View open source insights on deps.dev
Purl
pkg:golang/github.com/apache/servicecomb-service-center

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.0