One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 8288367
Date de publication 2022-12-06 18:15:10 (vue: 2022-12-06 20:07:18)
Titre CVE-2022-23470
Texte Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects Galaxy 22.01 and higher, after the switch to gunicorn, which serve static contents directly. Additionally, the vulnerability is mitigated when using Nginx or Apache to serve /static/* contents, instead of Galaxy's internal middleware. This issue has been patched in commit `e5e6bda4f` and will be included in future releases. Users are advised to manually patch their installations. There are no known workarounds for this vulnerability.
Notes
Envoyé Oui
Condensat /static/* 2022 23470 `e5e6bda4f` accessible additionally advised affects after analysis any apache arbitrary are been can commit contents cve data directly due exists file future galaxy gunicorn has higher included installations instead internal issue known manually middleware mitigated nginx open operating patch patched platform read releases running serve source static switch system under used user users using vulnerability when which will workarounds
Tags Vulnerability
Stories
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: