GHSL-2021-1009: URL access filters bypass in Alpine - CVE-2022-23553
Published Dec 22, 2022
·Updated
URL access filters (block and allow list) are subject to be bypassed
Affected Software
1 affected component
Alpine Alpine
Event History
Dec 22, 2022
Advisory Published
via GitHub Security Lab·12:00 AM
Data Sourced
via GitHub Security Lab·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of GHSL-2021-1009?
The severity of GHSL-2021-1009 is rated at 45.
2
How do I fix GHSL-2021-1009?
To fix GHSL-2021-1009, upgrade to the latest version of Alpine as indicated in the release notes.
3
What causes GHSL-2021-1009 vulnerability?
GHSL-2021-1009 is caused by insufficient URL access filters allowing bypass of block and allow lists.
4
What systems are affected by GHSL-2021-1009?
GHSL-2021-1009 affects versions of the Alpine software that utilize URL access filters.
5
Is there a workaround for GHSL-2021-1009?
There is no official workaround for GHSL-2021-1009; patching to a secure version is recommended.