CVE-2024-8260
7.3
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.3 / Impact: 5.9
Source: NVD
Description
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.
Affected (1)
Products: Openpolicyagent: Open Policy Agent
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 0.68.0 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (1)
Source: vulnreport@tenable.com
Third Party Advisory
Timeline
No history available yet.