CVE-2022-34296: High severity zalando skipper vulnerability
Published Jun 22, 2022
·Updated
In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
Affected Software
2 affected componentsFixes available
go/github.com/zalando/skipper<0.13.218
0.13.218
Zalando Skipper<0.13.218
Remediation
Patch Available
Event History
Jun 22, 2022
CVE Published
via MITRE·12:57 PM
Data Sourced
via MITRE·12:57 PM
Description
Jun 24, 2022
Advisory Published
12:00 AM
Frequently Asked Questions
1
Which deployments are affected?
Zalando Skipper versions before 0.13.218 are affected. Deployments running version 0.13.218 or later are not identified as affected by the provided information.
2
Does exploitation require authentication or user interaction?
No. The supplied CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction.
3
What is the impact of a successful exploit?
A prepared request can bypass a query predicate, resulting in an integrity impact. The supplied vector indicates no confidentiality or availability impact.
4
What should teams do to remediate the issue?
Apply the available patch by upgrading Zalando Skipper to version 0.13.218 or later.