gist.github.com
https://gist.github.com/nyxfqq/1a8237f3f9cf793c6433f08b17d1593c CVE-2024-41265
cortex establishes TLS connections with `InsecureSkipVerify` set to `true`
Description
A TLS certificate verification issue discovered in cortex v0.42.1 allows attackers to obtain sensitive information via the makeOperatorRequest function.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 2, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | Through 0.42.1 | affected |
github.com/cortexproject/cortexBrowse Go / github.com/cortexproject/cortex | GitHub Advisory | Through 0.42.1 | affected |
References
5github.com
https://github.com/advisories/GHSA-vw7g-3cc7-7rmh github.com
https://github.com/cortexproject/cortex nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-41265 pkg.go.dev
https://pkg.go.dev/vuln/GO-2024-3036