Vulnerability Report: GO-2024-3141
- CVE-2024-8260, GHSA-c77r-fh37-x2px
- Affects: github.com/open-policy-agent/opa
- Published: Sep 20, 2024
OPA for Windows has an SMB force-authentication vulnerability. Due to improper input validation, it allows a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.
Affected Packages
-
PathGo VersionsSymbols
-
before v0.68.0
Aliases
References
- https://github.com/open-policy-agent/opa/commit/10f4d553e6bb6ae9c69611ecdd9a77dda857070e
- https://www.tenable.com/security/research/tra-2024-36
- https://vuln.go.dev/ID/GO-2024-3141.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.