PT-2023-12728 · Unknown · Scs-Library-Client+1

Trudg

·

Publicado

2023-01-17

·

Atualizado

2024-06-20

·

CVE-2022-23538

CVSS v3.1

5.2

Média

VetorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions scs-library-client versions prior to 1.3.4 and 1.4.2
Description The HTTP Authorization header sent by the scs-library-client to the library service may be incorrectly leaked to an S3 backing storage provider when pulling a container image with authentication. This occurs in a specific flow where the library service redirects the client to a backing S3 storage server for a multi-part concurrent download. An attacker with access to the S3 service may be able to extract user credentials, allowing them to impersonate the user. The vulnerable flow is only used when communicating with a Singularity Enterprise 1.x installation or a third-party server implementing this flow.
Recommendations Update to scs-library-client version 1.3.4 or 1.4.2 to fix the security issue. For users interacting with a Singularity Enterprise 1.x installation using a 3rd party S3 storage service, revoke and recreate authentication tokens within Singularity Enterprise. As a temporary measure, consider avoiding the use of the multi-part concurrent download flow with redirect to S3 until the issue is resolved.

Exploit

Correção

Insufficiently Protected Credentials

Open Redirect

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2022-23538
GHSA-7P8M-22H4-9PJ7
GO-2023-1497
OPENSUSE-SU-2024:12694-1
OPENSUSE-SU-2024:14059-1

Produtos afetados

Singularity Enterprise
Scs-Library-Client