VDB
RHSA-2023%3A0814
RHSA-2023%3A0814
PUBLISHED
CVSS 9.100000381469727 CRITICAL
A flaw was found in CORS Filter feature from the go-restful package. When a user inputs a domain which is in AllowedDomains, all domains starting with the same pattern are accepted. This issue could allow an attacker to break the CORS policy by allowing any page to make requests and retrieve data on behalf of users.
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | cryostat-tech-preview/cryostat-reports-rhel8@sha256:3ae672568790ef1d2e0870d4c016186b37365144082920510dbd2426b336a896_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-tech-preview/cryostat-reports-rhel8@sha256:3ae672568790ef1d2e0870d4c016186b37365144082920510dbd2426b336a896_amd64 |
| Red Hat | cryostat-tech-preview/cryostat-rhel8-operator@sha256:20ab3fc7104fe007eb9d5d0df368b86ed6d01a9cb0c2b4595bcf9b677e7a22f8_amd64 as a component of Cryostat 2 on RHEL 8 | * |
| Red Hat | cryostat-tech-preview/cryostat-rhel8@sha256:3bec4e0d5e0e7f0a86374661222e68590f14181f230444a8a042904e772db9db_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-tech-preview/cryostat-rhel8@sha256:3bec4e0d5e0e7f0a86374661222e68590f14181f230444a8a042904e772db9db_amd64 |
| Red Hat | cryostat-tech-preview/jfr-datasource-rhel8@sha256:2718b97731f10e50c53a1e86e00d3fbb80a99b7fa0151858a6e355c501e1b392_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-tech-preview/jfr-datasource-rhel8@sha256:2718b97731f10e50c53a1e86e00d3fbb80a99b7fa0151858a6e355c501e1b392_amd64 |
| Red Hat | cryostat-tech-preview/cryostat-operator-bundle@sha256:704d50bc5a2ba7910344e6ec6d30bbabccd560628ac82b89d66f53a2ddf1140e_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-tech-preview/cryostat-operator-bundle@sha256:704d50bc5a2ba7910344e6ec6d30bbabccd560628ac82b89d66f53a2ddf1140e_amd64 |
| Red Hat | cryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:475397e4ba392d1bf197280f078b2aa024ee562ab0b4772b15b9fd773f52e716_amd64 as a component of Cryostat 2 on RHEL 8 | cryostat-tech-preview/cryostat-grafana-dashboard-rhel8@sha256:475397e4ba392d1bf197280f078b2aa024ee562ab0b4772b15b9fd773f52e716_amd64 |
Timeline
- Feb 20, 2023 CVE Published
- Mar 18, 2026 CVE Updated
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2023:0814 advisory
- https://access.redhat.com/security/updates/classification/#important advisory
- https://access.redhat.com/errata/RHSA-2023:0625 advisory
- https://access.redhat.com/containers advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2094982 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2161571 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2023/rhsa-2023_0814.json advisory
- https://access.redhat.com/security/cve/CVE-2022-1996 advisory
- https://www.cve.org/CVERecord?id=CVE-2022-1996 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-1996 advisory