GHSA-v5m8-5455-qw2x

Suggest an improvement
Source
https://github.com/advisories/GHSA-v5m8-5455-qw2x
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v5m8-5455-qw2x/GHSA-v5m8-5455-qw2x.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-v5m8-5455-qw2x
Aliases
Published
2026-06-10T15:31:33Z
Modified
2026-08-18T15:10:37Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N CVSS Calculator
Summary
Openshift Migration Advisor: Broken access control in migration-planner image-url endpoint exposes other users' OVA images and agent JWTs
Details

A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the /api/v1/sources/{id}/image-url endpoint. This flaw allows the attacker to bypass an ownership check and obtain presigned S3 URLs for Open Virtual Appliance (OVA) images belonging to other users. Consequently, the attacker can download OVA images containing sensitive information, such as long-lived agent JSON Web Tokens (JWTs) and source configurations, potentially leading to unauthorized access and modification of the victim's source.

Database specific
{
    "cwe_ids": [
        "CWE-639"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-08-14T15:37:35Z",
    "nvd_published_at": "2026-06-10T15:16:41Z",
    "severity": "CRITICAL"
}
References

Affected packages

Go / github.com/kubev2v/migration-planner

Package

Name
github.com/kubev2v/migration-planner
View open source insights on deps.dev
Purl
pkg:golang/github.com/kubev2v/migration-planner

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.13.5

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-v5m8-5455-qw2x/GHSA-v5m8-5455-qw2x.json"