{ "id": "CVE-2024-32980", "sourceIdentifier": "security-advisories@github.com", "published": "2024-05-08T15:15:10.530", "lastModified": "2024-05-08T17:05:24.083", "vulnStatus": "Awaiting Analysis", "cveTags": [], "descriptions": [ { "lang": "en", "value": "Spin is the developer tool for building and running serverless applications powered by WebAssembly. Prior to 2.4.3, some specifically configured Spin applications that use `self` requests without a specified URL authority can be induced to make requests to arbitrary hosts via the `Host` HTTP header. The following conditions need to be met for an application to be vulnerable: 1. The environment Spin is deployed in routes requests to the Spin runtime based on the request URL instead of the `Host` header, and leaves the `Host` header set to its original value; 2. The Spin application's component handling the incoming request is configured with an `allow_outbound_hosts` list containing `\"self\"`; and 3. In reaction to an incoming request, the component makes an outbound request whose URL doesn't include the hostname/port. Spin 2.4.3 has been released to fix this issue." }, { "lang": "es", "value": "Spin es la herramienta de desarrollo para crear y ejecutar aplicaciones sin servidor impulsadas por WebAssembly. Antes de 2.4.3, algunas aplicaciones Spin configuradas espec\u00edficamente que usan solicitudes \"autom\u00e1ticas\" sin una autoridad de URL especificada pueden ser inducidas a realizar solicitudes a hosts arbitrarios a trav\u00e9s del encabezado HTTP \"Host\". Se deben cumplir las siguientes condiciones para que una aplicaci\u00f3n sea vulnerable: 1. El entorno Spin se implementa en rutas de solicitudes al tiempo de ejecuci\u00f3n de Spin seg\u00fan la URL de solicitud en lugar del encabezado \"Host\", y deja el encabezado \"Host\" configurado en su valor original; 2. El componente de la aplicaci\u00f3n Spin que maneja la solicitud entrante est\u00e1 configurado con una lista `allow_outbound_hosts` que contiene `\"self\"`; y 3. En reacci\u00f3n a una solicitud entrante, el componente realiza una solicitud saliente cuya URL no incluye el nombre de host/puerto. Se lanz\u00f3 Spin 2.4.3 para solucionar este problema." } ], "metrics": { "cvssMetricV31": [ { "source": "security-advisories@github.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "NONE", "baseScore": 9.1, "baseSeverity": "CRITICAL" }, "exploitabilityScore": 3.9, "impactScore": 5.2 } ] }, "weaknesses": [ { "source": "security-advisories@github.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-610" } ] } ], "references": [ { "url": "https://github.com/fermyon/spin/commit/b3db535c9edb72278d4db3a201f0ed214e561354", "source": "security-advisories@github.com" }, { "url": "https://github.com/fermyon/spin/security/advisories/GHSA-f3h7-gpjj-wcvh", "source": "security-advisories@github.com" } ] }