CVE-2022-23470

Galaxy is an open-source platform for data analysis. An arbitrary file read exists in Galaxy 22.01 and Galaxy 22.05 due to the switch to Gunicorn, which can be used to read any file accessible to the operating system user under which Galaxy is running. This vulnerability affects Galaxy 22.01 and higher, after the switch to gunicorn, which serve static contents directly. Additionally, the vulnerability is mitigated when using Nginx or Apache to serve /static/* contents, instead of Galaxy's internal middleware. This issue has been patched in commit `e5e6bda4f` and will be included in future releases. Users are advised to manually patch their installations. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:galaxyproject:galaxy:*:*:*:*:*:*:*:*

History

21 Nov 2024, 06:48

Type Values Removed Values Added
Summary
  • (es) Galaxy es una plataforma de código abierto para análisis de datos. Existe una lectura de archivo arbitraria en Galaxy 22.01 y Galaxy 22.05 debido al cambio a Gunicorn, que se puede usar para leer cualquier archivo accesible para el usuario del sistema operativo bajo el cual se ejecuta Galaxy. Esta vulnerabilidad afecta a Galaxy 22.01 y superiores, después del cambio a gunicorn, que sirve contenidos estáticos directamente. Además, la vulnerabilidad se mitiga cuando se utiliza Nginx o Apache para servir contenidos /static/*, en lugar del middleware interno de Galaxy. Este problema se solucionó en el commit `e5e6bda4f` y se incluirá en versiones futuras. Se recomienda a los usuarios que parcheen manualmente sus instalaciones. No se conocen workarounds para esta vulnerabilidad.
CVSS v2 : unknown
v3 : 7.5
v2 : unknown
v3 : 8.6
References () https://github.com/galaxyproject/galaxy/commit/e5e6bda4f014f807ca77ee0cf6af777a55918346 - Patch, Third Party Advisory () https://github.com/galaxyproject/galaxy/commit/e5e6bda4f014f807ca77ee0cf6af777a55918346 - Patch, Third Party Advisory
References () https://github.com/galaxyproject/galaxy/security/advisories/GHSA-grjf-2ghx-q77x - Patch, Third Party Advisory () https://github.com/galaxyproject/galaxy/security/advisories/GHSA-grjf-2ghx-q77x - Patch, Third Party Advisory

Information

Published : 2022-12-06 18:15

Updated : 2024-11-21 06:48


NVD link : CVE-2022-23470

Mitre link : CVE-2022-23470

CVE.ORG link : CVE-2022-23470


JSON object : View

Products Affected

galaxyproject

  • galaxy
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')