minder
cpe:2.3:a:lfprojects:minder:*:*:*:*:go:*:*
- 0.20241106.3386+ref.2507dbf
- 0.0.72
- 0.0.73
- 0.0.74
- 0.0.75
- 0.0.76
- 0.0.77
- 0.0.78
- 0.0.79
- 0.0.80
- 0.0.81
- 0.0.82
- 0.0.83
A vulnerability exists in Minder Helm version 0.20241106.3386+ref.2507dbf and Minder Go versions 0.0.72 to 0.0.83, allowing users to fetch content that may include restricted URLs. This could be problematic if the Minder server is behind a firewall or network partition. The issue arises because Minder does not sandbox HTTP requests in Rego programs, potentially exposing sensitive resources depending on the deployment configuration.
Exploitation of this vulnerability could lead to unauthorized access to URLs and resources that the user would typically be unable to reach, such as services behind a firewall or network partition.
This vulnerability can be reproduced by deploying Minder Helm or Go versions within the affected range and then using the HTTP send capability in a Rego program. This will fetch content from the Minder server context, potentially including sensitive URLs that are normally inaccessible.
Users should upgrade to Minder Helm version 0.20250203.3849+ref.fdc94f0 or Minder Go version 0.0.84. Avoid deploying Minder with access to sensitive resources, especially systems like OpenFGA or Keycloak, depending on the deployment configuration.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.