Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

x/vulndb: potential Go vuln in github.com/labring/sealos: GHSA-vpxf-q44g-w34w #1880

Closed
GoVulnBot opened this issue Jun 30, 2023 · 5 comments
Closed
Assignees
Labels
excluded: NOT_IMPORTABLE This vulnerability only exists in a binary and is not importable.

Comments

@GoVulnBot
Copy link

In GitHub Security Advisory GHSA-vpxf-q44g-w34w, there is a vulnerability in the following Go packages or modules:

Unit Fixed Vulnerable Ranges
github.com/labring/sealos <= 4.2.0

Cross references:
No existing reports found with this module or alias.

See doc/triage.md for instructions on how to triage this report.

modules:
    - module: github.com/labring/sealos
      versions:
        - {}
      vulnerable_at: 1.14.0
      packages:
        - package: github.com/labring/sealos
summary: Sealos billing system permission control defect
description: |-
    ### Summary

    There is a permission flaw in the Sealos billing system, which allows users to
    control the recharge resource account. sealos. io/v1/Payment, resulting in the
    ability to recharge any amount of 1 RMB.

    ### Details

    The reason is that sealos is in arrears. Egg pain, we can't create a terminal
    anymore. Let's charge for it:

    Then it was discovered that the charging interface had returned all resource
    information. Unfortunately, based on previous vulnerability experience, the
    namespace of this custom resource is still under the current user's control and
    may have permission to correct it.

    ### PoC disable by publish

    ### Impact

    + sealos public cloud user
    + CWE-287 Improper Authentication
ghsas:
    - GHSA-vpxf-q44g-w34w
references:
    - advisory: https://github.com/labring/sealos/security/advisories/GHSA-vpxf-q44g-w34w
    - advisory: https://github.com/advisories/GHSA-vpxf-q44g-w34w

@jba jba self-assigned this Jul 5, 2023
@jba
Copy link
Contributor

jba commented Jul 5, 2023

This project seems to be a collection of binaries. I didn't seen any outside importers of the non-main packages.

@jba jba added the excluded: NOT_IMPORTABLE This vulnerability only exists in a binary and is not importable. label Jul 5, 2023
@gopherbot
Copy link
Contributor

Change https://go.dev/cl/507896 mentions this issue: data/excluded: batch add 10 excluded reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/507901 mentions this issue: data/excluded: batch add 8 excluded reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/507904 mentions this issue: data/excluded: batch add 8 excluded reports

@gopherbot
Copy link
Contributor

Change https://go.dev/cl/592761 mentions this issue: data/reports: unexclude 75 reports

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
excluded: NOT_IMPORTABLE This vulnerability only exists in a binary and is not importable.
Projects
None yet
Development

No branches or pull requests

3 participants