In Zalando Skipper before 0.13.218, a query predicate could be bypassed via a prepared request.
References
Link | Resource |
---|---|
https://github.com/zalando/skipper/releases/tag/v0.13.218 | Exploit Patch Release Notes Third Party Advisory |
Configurations
Information
Published : 2022-06-23 10:15
Updated : 2022-07-06 09:29
NVD link : CVE-2022-34296
Mitre link : CVE-2022-34296
JSON object : View
CWE
CWE-863
Incorrect Authorization
Products Affected
zalando
- skipper