Vulnerability Description
Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within the orca container via authenticated HTTP POST requests.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Spinnaker | < 1.21.5 |
Related Weaknesses (CWE)
References
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-0PatchThird Party Advisory
- https://github.com/Netflix/security-bulletins/blob/master/advisories/nflx-2020-0PatchThird Party Advisory
FAQ
What is CVE-2020-9301?
CVE-2020-9301 is a vulnerability with a CVSS score of 8.8 (HIGH). Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL...
How severe is CVE-2020-9301?
CVE-2020-9301 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-9301?
Check the references section above for vendor advisories and patch information. Affected products include: Linuxfoundation Spinnaker.