PT-2023-23001 · Unknown · Typed-Rest-Client

Jlleitschuh

·

Publicado

2023-04-26

·

Atualizado

2023-06-01

·

CVE-2023-30846

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions typed-rest-client versions 1.7.3 and earlier
Description The typed-rest-client library is vulnerable to leaking authentication data to third parties. This occurs when a request is sent with BasicCredentialHandler, BearerCredentialHandler, or PersonalAccessTokenCredentialHandler, and the target host returns a redirection with a link to a second host. The next request will then use the credentials to authenticate with the second host by setting the Authorization header, which is not the expected behavior. The problem was fixed in version 1.8.0.
Recommendations For typed-rest-client versions 1.7.3 and earlier, update to version 1.8.0 to resolve the issue. As a temporary workaround, consider disabling the use of BasicCredentialHandler, BearerCredentialHandler, and PersonalAccessTokenCredentialHandler until the update is applied. Restrict access to sensitive resources that may be exposed due to this vulnerability.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-30846
GHSA-558P-M34M-VPMQ

Produtos afetados

Typed-Rest-Client