CVE-2022-39219

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-39219
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39219.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2022-39219
Aliases
Related
Published
2022-09-26T14:15:10Z
Modified
2025-01-14T11:06:27.388199Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N CVSS Calculator
Summary
[none]
Details

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

References

Affected packages

Git / github.com/brokercap/bifrost

Affected ranges

Type
GIT
Repo
https://github.com/brokercap/bifrost
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

MySQL_Filed_DataCheck_v0.*

MySQL_Filed_DataCheck_v0.1.0
MySQL_Filed_DataCheck_v0.1.1

Other

v1

v1.*

v1.0.0-release
v1.0.1-release
v1.0.2-release
v1.0.3-release
v1.0.4-release
v1.1.0
v1.1.0-beta.07-04
v1.1.0-beta.08
v1.1.0-beta.09
v1.1.0-beta.10
v1.1.0-beta.11
v1.1.0-beta.12
v1.1.0-beta.13
v1.1.0-beta.14
v1.1.0-beta.15
v1.1.0-beta.16
v1.1.0-beta.16.apha01
v1.1.0-beta.17
v1.1.0-beta.18
v1.1.0-beta.19
v1.1.0-beta.20
v1.1.0-beta.21
v1.1.0-release
v1.1.1-release
v1.2.0-rc.01
v1.2.1-rc.01
v1.2.1-release
v1.2.2
v1.2.2-release
v1.2.3-release
v1.2.4-release
v1.2.x-beta.01
v1.3.0-release
v1.3.1-release
v1.3.2-release
v1.4.0-release
v1.4.1-release
v1.4.2-release
v1.4.3-release
v1.4.4-release
v1.4.5-release
v1.5.0-beta.01
v1.5.0-release
v1.5.1-release
v1.5.2-release
v1.6.0-beta.01
v1.6.0-beta.02
v1.6.0-beta.04
v1.6.0-release
v1.6.1-release
v1.6.2-release
v1.6.3-release
v1.6.4-release
v1.6.5-release
v1.6.6-release
v1.7.0-rc.01
v1.7.1-release
v1.7.2-release
v1.7.3-release
v1.7.4-release
v1.8.0-beta.01
v1.8.1-release
v1.8.2-release
v1.8.3-release
v1.8.4-release
v1.8.5-release
v1.8.6-release