Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2556 | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. |
Github GHSA |
GHSA-c77r-fh37-x2px | OPA for Windows has an SMB force-authentication vulnerability |
Wed, 11 Dec 2024 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat openshift Distributed Tracing |
|
| CPEs | cpe:/a:redhat:openshift_distributed_tracing:3.4::el8 | |
| Vendors & Products |
Redhat
Redhat openshift Distributed Tracing |
Thu, 19 Sep 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows Openpolicyagent Openpolicyagent open Policy Agent |
|
| CPEs | cpe:2.3:a:openpolicyagent:open_policy_agent:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows Openpolicyagent Openpolicyagent open Policy Agent |
Mon, 02 Sep 2024 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 30 Aug 2024 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 30 Aug 2024 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions. | |
| Title | OPA SMB Force-Authentication | |
| Weaknesses | CWE-294 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-30T13:17:20.246Z
Reserved: 2024-08-28T12:18:55.569Z
Link: CVE-2024-8260
Updated: 2024-08-30T13:17:16.045Z
Status : Analyzed
Published: 2024-08-30T13:15:12.347
Modified: 2024-09-19T16:08:58.863
Link: CVE-2024-8260
OpenCVE Enrichment
No data.
EUVD
Github GHSA