CVE-2022-39219

Source
https://nvd.nist.gov/vuln/detail/CVE-2022-39219
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-39219.json
Aliases
Published
2022-09-26T14:15:10Z
Modified
2023-11-29T09:49:15.138738Z
Details

Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.

References

Affected packages

Git / github.com/brokercap/bifrost

Affected ranges

Type
GIT
Repo
https://github.com/brokercap/bifrost
Events
Introduced
0The exact introduced commit is unknown
Fixed

Affected versions

MySQL_Filed_DataCheck_v0.*

MySQL_Filed_DataCheck_v0.1.0
MySQL_Filed_DataCheck_v0.1.1

Other

v1

v1.*

v1.0.0-release
v1.0.1-release
v1.0.2-release
v1.0.3-release
v1.0.4-release
v1.1.0
v1.1.0-beta.07-04
v1.1.0-beta.08
v1.1.0-beta.09
v1.1.0-beta.10
v1.1.0-beta.11
v1.1.0-beta.12
v1.1.0-beta.13
v1.1.0-beta.14
v1.1.0-beta.15
v1.1.0-beta.16
v1.1.0-beta.16.apha01
v1.1.0-beta.17
v1.1.0-beta.18
v1.1.0-beta.19
v1.1.0-beta.20
v1.1.0-beta.21
v1.1.0-release
v1.1.1-release
v1.2.0-rc.01
v1.2.1-rc.01
v1.2.1-release
v1.2.2
v1.2.2-release
v1.2.3-release
v1.2.4-release
v1.2.x-beta.01
v1.3.0-release
v1.3.1-release
v1.3.2-release
v1.4.0-release
v1.4.1-release
v1.4.2-release
v1.4.3-release
v1.4.4-release
v1.4.5-release
v1.5.0-beta.01
v1.5.0-release
v1.5.1-release
v1.5.2-release
v1.6.0-beta.01
v1.6.0-beta.02
v1.6.0-beta.04
v1.6.0-release
v1.6.1-release
v1.6.2-release
v1.6.3-release
v1.6.4-release
v1.6.5-release
v1.6.6-release
v1.7.0-rc.01
v1.7.1-release
v1.7.2-release
v1.7.3-release
v1.7.4-release
v1.8.0-beta.01
v1.8.1-release
v1.8.2-release
v1.8.3-release
v1.8.4-release
v1.8.5-release
v1.8.6-release