You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Description:
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no known workarounds.
See doc/triage.md for instructions on how to triage this report.
modules:
- module: github.com/brokercap/Bifrost
packages:
- package: Bifrost
description: "Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB
to Redis, MongoDB, ClickHouse, MySQL and other services for production environments.
Versions prior to 1.8.8-release are subject to authentication bypass in the admin
and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field
in the request header. This issue has been patched in 1.8.8-release. There are
no known workarounds. \n"
cves:
- CVE-2022-39267
references:
- web: https://github.com/brokercap/Bifrost/security/advisories/GHSA-mxrx-fg8p-5p5j
- fix: https://github.com/brockercap/Bifrost/pull/201
The text was updated successfully, but these errors were encountered:
CVE-2022-39267 references github.com/brokercap/Bifrost, which may be a Go module.
Description:
Bifrost is a heterogeneous middleware that synchronizes MySQL, MariaDB to Redis, MongoDB, ClickHouse, MySQL and other services for production environments. Versions prior to 1.8.8-release are subject to authentication bypass in the admin and monitor user groups by deleting the X-Requested-With: XMLHttpRequest field in the request header. This issue has been patched in 1.8.8-release. There are no known workarounds.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: