CVE-2022-23553

Alpine is a scaffolding library in Java. Alpine prior to version 1.10.4 allows URL access filter bypass. This issue has been fixed in version 1.10.4. There are no known workarounds.
Configurations

Configuration 1 (hide)

cpe:2.3:a:alpine_project:alpine:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
References () https://github.com/stevespringett/Alpine/blob/alpine-parent-1.10.2/alpine/src/main/java/alpine/filters/BlacklistUrlFilter.java#L107-L121 - Third Party Advisory () https://github.com/stevespringett/Alpine/blob/alpine-parent-1.10.2/alpine/src/main/java/alpine/filters/BlacklistUrlFilter.java#L107-L121 - Third Party Advisory
References () https://github.com/stevespringett/Alpine/blob/alpine-parent-1.10.2/alpine/src/main/java/alpine/filters/WhitelistUrlFilter.java#L115-L127 - Third Party Advisory () https://github.com/stevespringett/Alpine/blob/alpine-parent-1.10.2/alpine/src/main/java/alpine/filters/WhitelistUrlFilter.java#L115-L127 - Third Party Advisory
References () https://securitylab.github.com/advisories/GHSL-2021-1009-Alpine/ - Third Party Advisory () https://securitylab.github.com/advisories/GHSL-2021-1009-Alpine/ - Third Party Advisory

11 Jul 2023, 20:42

Type Values Removed Values Added
CWE CWE-863 NVD-CWE-Other

Information

Published : 2022-12-28 19:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23553

Mitre link : CVE-2022-23553

CVE.ORG link : CVE-2022-23553


JSON object : View

Products Affected

alpine_project

  • alpine
CWE
CWE-863

Incorrect Authorization

NVD-CWE-Other