CVE-2023-39348
Last modified
CVE-2023-39348 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Spinnaker is an open source, multi-cloud continuous delivery platform. Log output when updating GitHub status is improperly set to FULL always. It's recommended to apply the patch and rotate the GitHub token used for github status notifications. Given that this would output github tokens to a log system, the risk is slightly higher than a "low" since token exposure could grant elevated access to repositories outside of control. If using READ restricted tokens, the exposure is such that the token itself could be used to access resources otherwise restricted from reads. This only affects users of GitHub Status Notifications. This issue has been addressed in pull request 1316. Users are advised to upgrade. Users unable to upgrade should disable GH Status Notifications, Filter their logs for Echo log data and use read-only tokens that are limited in scope.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linuxfoundation | Spinnaker | < 1.28.8 |
| Linuxfoundation | Spinnaker | >= 1.29.0, < 1.29.6 |
| Linuxfoundation | Spinnaker | >= 1.30.0, < 1.30.3 |
| Linuxfoundation | Spinnaker | 1.30.0 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-39348?
How severe is CVE-2023-39348?
How do I fix CVE-2023-39348?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-39342Dangerzone is software for converting potentially dangerous …3.6
- CVE-2023-39343Sulu is an open-source PHP content management system based o…4.3
- CVE-2023-39344social-media-skeleton is an uncompleted social media project…8.8
- CVE-2023-39345strapi is an open-source headless CMS. Versions prior to 4.1…7.5
- CVE-2023-39346LinuxASMCallGraph is software for drawing the call graph of …9.8
- CVE-2023-39347Cilium is a networking, observability, and security solution…9
- CVE-2023-39349Sentry is an error tracking and performance monitoring platf…8.1
- CVE-2023-3935A heap buffer overflow vulnerability in Wibu CodeMeter Runti…9.8
- CVE-2023-39350FreeRDP is a free implementation of the Remote Desktop Proto…7.5
- CVE-2023-39351FreeRDP is a free implementation of the Remote Desktop Proto…7.5
- CVE-2023-39352FreeRDP is a free implementation of the Remote Desktop Proto…9.8
- CVE-2023-39353FreeRDP is a free implementation of the Remote Desktop Proto…9.1
Are you affected by CVE-2023-39348?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
