CVE-2022-39383

MEDIUM

KubeVela < 1.5.9 and 1.6.0-alpha.1-1.6.2 - Server-Side Request Forgery via Helm Chart Warehouse Request

Title source: llm
STIX 2.1

Description

KubeVela is an open source application delivery platform. Users using the VelaUX APIServer could be affected by this vulnerability. When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability. Users who're using v1.6, please update the v1.6.1. Users who're using v1.5, please update the v1.5.8. There are no known workarounds for this issue.

References (2)

Core 2

Scores

CVSS v3 4.9
EPSS 0.0021
EPSS Percentile 42.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-918
Status published
Products (2)
linuxfoundation/kubevela < 1.5.9
oam-dev/kubevela 1.6.0-alpha.1 - 1.6.2Go
Published Nov 16, 2022
Tracked Since Feb 18, 2026