GHSA-9pc8-m4vp-ggvf

    Dashboard / Vulnerabilities / GHSA-9pc8-m4vp-ggvf

    GHSA-9pc8-m4vp-ggvf

    Published: 19 Oct 2023Last Modified: 21 Aug 2024

    Summary: Artifact Hub allows unsafe rego built-in

    Details: ### Impact During a security audit of Artifact Hub's code base, a security researcher at [OffSec](https://www.offsec.com/) identified a bug in which a default unsafe rego built-in was allowed to be used when defining authorization policies. Artifact Hub includes a fine-grained authorization mechanism that allows organizations to define what actions can be performed by their members. It is based on customizable authorization policies that are enforced by the [Open Policy Agent](https://www.openpolicyagent.org/). Policies are written using [rego](https://www.openpolicyagent.org/docs/latest/#rego) and their data files are expected to be json documents. By default, `rego` allows policies to make HTTP requests, which can be abused to send requests to internal resources and forward the responses to an external entity. In the context of Artifact Hub, this capability should have been disabled. ### Patches This issue has been resolved in version [1.16.0](https://artifacthub.io/packages/helm/artifact-hub/artifact-hub?modal=changelog&version=1.16.0).

    Affected packages

    Package

    Name: github.com/artifacthub/hub

    Purl: pkg:golang/github.com/artifacthub/hub

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.16.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-9pc8-m4vp-ggvf | CVE-DB