CVE-2024-35223

May 23, 2024, 9:15 a.m.

Received
CVE has been recently published to the CVE List and has been received by the NVD.

Products

Dapr

  • 1.0 - 1.13.2

Source

security-advisories@github.com

Tags

CVE-2024-35223 details

Published : May 23, 2024, 9:15 a.m.
Last Modified : May 23, 2024, 9:15 a.m.

Description

Dapr is a portable, event-driven, runtime for building distributed applications across cloud and edge. Dapr sends the app token of the invoker app instead of the app token of the invoked app. This causes of a leak of the application token of the invoker app to the invoked app when using Dapr as a gRPC proxy for remote service invocation. This vulnerability impacts Dapr users who use Dapr as a gRPC proxy for remote service invocation as well as the Dapr App API token functionality. An attacker could exploit this vulnerability to gain access to the app token of the invoker app, potentially compromising security and authentication mechanisms. This vulnerability was patched in version 1.13.3.

CVSS Score

1 2 3 4 5.3 6 7 8 9 10

Weakness

Weakness Name Description

CVSS Data

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

Base Score

5.3

Exploitability Score

Impact Score

Base Severity

MEDIUM

References

URL Source
https://github.com/dapr/dapr/commit/e0591e43d0cdfd30a2f2960dce5d9892dc98bc2c security-advisories@github.com
https://github.com/dapr/dapr/issues/7344 security-advisories@github.com
https://github.com/dapr/dapr/pull/7404 security-advisories@github.com
https://github.com/dapr/dapr/releases/tag/v1.13.3 security-advisories@github.com
https://github.com/dapr/dapr/security/advisories/GHSA-284c-x8m7-9w5h security-advisories@github.com
This website uses the NVD API, but is not approved or certified by it.