MEDIUM 4.9 Go
KubeVela VelaUX APIserver has SSRF vulnerability
GHSA-m5xf-x7q6-3rm7 · CVE-2022-39383 · GO-2022-1113
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Users using the VelaUX APIServer could be affected by this vulnerability.
When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.
This issue is patched in 1.5.9 and 1.6.2.
References
Fix by: #5000
For more information
If you have any questions or comments about this advisory:
- Open an issue in KubeVela repo
- Email us at here
Ready to move
Start Securing
Free, no credit card | First findings in minutes