
We found results for “”
CVE-2022-36085
Good to know:

Date: September 8, 2022
Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) "WithUnsafeBuiltins" function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler if encountered in the policy compilation stage. A bypass of this protection has been found, where the use of the "with" keyword to mock such a built-in function (a feature introduced in OPA v0.40.0), isn’t taken into account by "WithUnsafeBuiltins". Multiple conditions need to be met in order to create an adverse effect. Version 0.43.1 contains a patch for this issue. As a workaround, avoid using the "WithUnsafeBuiltins" function and use the "capabilities" feature instead.
Language: Go
Severity Score
Related Resources (10)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Protection Mechanism Failure
CWE-693Insufficient Information
NVD-CWE-noinfoTop Fix

CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | UNCHANGED |
Confidentiality (C): | HIGH |
Integrity (I): | HIGH |
Availability (A): | NONE |