x/vulndb: potential Go vuln in github.com/brokercap/Bifrost: CVE-2022-39219 #1023
Labels
cve-year-2022
excluded: EFFECTIVELY_PRIVATE
This vulnerability exists in a package can be imported, but isn't meant to be outside that module.
CVE-2022-39219 references github.com/brokercap/Bifrost, which may be a Go module.
Description:
Bifrost is a middleware package which can synchronize MySQL/MariaDB binlog data to other types of databases. Versions 1.8.6-release and prior are vulnerable to authentication bypass when using HTTP basic authentication. This may allow group members who only have read permissions to write requests when they are normally forbidden from doing so. Version 1.8.7-release contains a patch. There are currently no known workarounds.
References:
See doc/triage.md for instructions on how to triage this report.
The text was updated successfully, but these errors were encountered: