Open Redirect Affecting kubeflow-pipelines package, versions <2.0.5-r2
Threat Intelligence
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-WOLFILATEST-KUBEFLOWPIPELINES-6186792
- published 24 Jan 2024
- disclosed 2 Jan 2024
Introduced: 2 Jan 2024
CVE-2023-26159 Open this link in a new tabHow to fix?
Upgrade Wolfi
kubeflow-pipelines
to version 2.0.5-r2 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kubeflow-pipelines
package and not the kubeflow-pipelines
package as distributed by Wolfi
.
See How to fix?
for Wolfi
relevant fixed versions and status.
Versions of the package follow-redirects before 1.15.4 are vulnerable to Improper Input Validation due to the improper handling of URLs by the url.parse() function. When new URL() throws an error, it can be manipulated to misinterpret the hostname. An attacker could exploit this weakness to redirect traffic to a malicious site, potentially leading to information disclosure, phishing attacks, or other security breaches.
References
- https://github.com/follow-redirects/follow-redirects/issues/235
- https://github.com/follow-redirects/follow-redirects/pull/236
- https://security.snyk.io/vuln/SNYK-JS-FOLLOWREDIRECTS-6141137
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZZ425BFKNBQ6AK7I5SAM56TWON5OF2XM/