blob: 7f04cfbcf2488236e7f78b3f8b9f59107b3e3dcb [file] [log] [blame]
id: GO-2025-3660
modules:
- module: github.com/open-policy-agent/opa
versions:
- fixed: 1.4.0
vulnerable_at: 1.3.0
packages:
- package: github.com/open-policy-agent/opa/v1/server
symbols:
- Server.unversionedGetHealthWithPolicy
- Server.makeRego
- stringPathToDataRef
- Server.v0QueryPath
- stringPathToRef
derived_symbols:
- baseHTTPListener.ListenAndServe
- baseHTTPListener.ListenAndServeTLS
summary: |-
OPA server Data API HTTP path injection of Rego in
github.com/open-policy-agent/opa
cves:
- CVE-2025-46569
ghsas:
- GHSA-6m8w-jc87-6cr7
references:
- advisory: https://github.com/open-policy-agent/opa/security/advisories/GHSA-6m8w-jc87-6cr7
- fix: https://github.com/open-policy-agent/opa/commit/ad2063247a14711882f18c387a511fc8094aa79c
source:
id: GHSA-6m8w-jc87-6cr7
created: 2025-05-05T11:20:27.529811-04:00
review_status: REVIEWED