PT-2023-6511 · Unknown · Soft Serve

Jjgadgets

·

Publicado

2023-10-02

·

Atualizado

2024-08-21

·

CVE-2023-43809

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Soft Serve versions prior to 0.6.2
Description A security issue in Soft Serve allows an unauthenticated, remote attacker to bypass public key authentication when keyboard-interactive SSH authentication is active, through the allow-keyless setting, and the public key requires additional client-side verification, for example, using FIDO2 or GPG. This is due to insufficient validation procedures of the public key step during SSH request handshake, granting unauthorized access if the keyboard-interaction mode is utilized. An attacker could exploit this by presenting manipulated SSH requests using keyboard-interactive authentication mode, potentially resulting in unauthorized access to Soft Serve.
Recommendations To resolve the issue, upgrade to Soft Serve version 0.6.2. As a temporary workaround, consider disabling Keyboard-Interactive SSH Authentication using the allow-keyless setting.

Exploit

Correção

Improper Authentication

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-07258
CVE-2023-43809
GHSA-MC97-99J4-VM2V
GO-2023-2097

Produtos afetados

Soft Serve