MEDIUM6.1
GHSA-c77r-fh37-x2px
OPA for Windows has an SMB force-authentication vulnerability
Quick fix
GHSA-c77r-fh37-x2px — github.com/open-policy-agent/opa: upgrade to the fixed version with the command below.
go get github.com/open-policy-agent/opa@v0.68.0Details
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/open-policy-agent/opa
Introduced in:
0Fixed in: 0.68.0Fix
go get github.com/open-policy-agent/opa@v0.68.0References
- https://nvd.nist.gov/vuln/detail/CVE-2024-8260[ADVISORY]
- https://github.com/open-policy-agent/opa/commit/10f4d553e6bb6ae9c69611ecdd9a77dda857070e[WEB]
- https://github.com/open-policy-agent/opa[PACKAGE]
- https://github.com/open-policy-agent/opa/releases/tag/v0.68.0[WEB]
- https://pkg.go.dev/vuln/GO-2024-3141[WEB]
- https://www.tenable.com/security/research/tra-2024-36[WEB]