{"id":"GO-2022-1113","summary":"Server-side request forgery in github.com/oam-dev/kubevela","details":"When using Helm Chart as the component delivery method, the request address of the warehouse is not restricted, and there is a blind SSRF vulnerability.","aliases":["CVE-2022-39383","GHSA-m5xf-x7q6-3rm7"],"modified":"2026-02-04T02:42:46.020152Z","published":"2022-12-07T18:45:56Z","related":["CGA-r59f-cj6h-534p"],"database_specific":{"url":"https://pkg.go.dev/vuln/GO-2022-1113","review_status":"REVIEWED"},"references":[{"type":"ADVISORY","url":"https://github.com/kubevela/kubevela/security/advisories/GHSA-m5xf-x7q6-3rm7"},{"type":"FIX","url":"https://github.com/kubevela/kubevela/pull/5000"}],"affected":[{"package":{"name":"github.com/oam-dev/kubevela","ecosystem":"Go","purl":"pkg:golang/github.com/oam-dev/kubevela"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.5.8"},{"introduced":"1.6.0"},{"fixed":"1.6.1"}]}],"ecosystem_specific":{"imports":[{"path":"github.com/oam-dev/kubevela/pkg/utils/common","symbols":["HTTPGetResponse"]}]},"database_specific":{"source":"https://vuln.go.dev/ID/GO-2022-1113.json"}}],"schema_version":"1.7.3"}