Intel

AIKIDO-2024-10172

github.com/zalando/skipper is vulnerable to Malicious Code

Malicious Code Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Jul 8, 2024

80

High Risk

This Affects:

gogithub.com/zalando/skipper
0.13.231 - 0.21.139
Fixed in 0.21.140
Are you affected? Scan for Free

TL;DR

github.com/zalando/skipper has a polyfill[.]io script link in its documentation, this library was taken over by attackers and serves malicious code.

Who does this affect?

You are affected if you are using a version which is within vulnerability ranges and if you are hosting the documentation site.

Background info

github.com/zalando/skipper is vulnerable to Malicious Code in versions 0.13.231 - 0.21.139.

How to fix this

Upgrade the github.com/zalando/skipper library to the patch version.