GHSA-54r5-wr8x-x5v3

Suggest an improvement
Source
https://github.com/advisories/GHSA-54r5-wr8x-x5v3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-54r5-wr8x-x5v3/GHSA-54r5-wr8x-x5v3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-54r5-wr8x-x5v3
Withdrawn
2024-10-07T21:00:34Z
Published
2022-12-20T00:30:27Z
Modified
2024-12-07T05:38:43Z
Severity
  • 7.1 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
Duplicate Advisory: Apiman has insufficient checks for read permissions
Details

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-j94p-hv25-rm5g. This link is maintained to preserve external references.

Original Description

Apiman 1.5.7 through 2.2.3.Final has insufficient checks for read permissions within the Apiman Manager REST API. A malicious user may be able to find and subscribe to private APIs they do not have permission for, thus accessing API Management-protected resources they should not be allowed to access. The root cause of the issue is the Apiman project's accidental acceptance of a large contribution that was not fully compatible with the security model of Apiman versions before 3.0.0.Final. Because of this, 3.0.0.Final is not affected by the vulnerability.

Database specific
{
    "cwe_ids":  [
        "CWE-276",
        "CWE-280"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2022-12-20T17:37:18Z",
    "nvd_published_at":  "2022-12-20T00:15:00Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / io.apiman:apiman-manager-api-rest-impl

Package

Name
io.apiman:apiman-manager-api-rest-impl
View open source insights on deps.dev
Purl
pkg:maven/io.apiman/apiman-manager-api-rest-impl

Affected ranges

Type
ECOSYSTEM
Events
Introduced
1.5.7
Fixed
3.0.0.Final

Affected versions

1.*
1.5.7.Final
2.*
2.0.0.Final
2.1.0.Final
2.1.1.Final
2.1.2.Final
2.1.3.Final
2.1.4.Final
2.1.5.Final
2.2.0.Final
2.2.1.Final
2.2.2.Final
2.2.3.Final
3.*
3.0.0.RC6

Database specific

last_known_affected_version_range
"<= 2.2.3.Final"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/12/GHSA-54r5-wr8x-x5v3/GHSA-54r5-wr8x-x5v3.json"