PT-2018-9567 · Luigi · Luigi

Published

2018-12-20

·

Updated

2019-02-07

·

CVE-2018-1000843

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Luigi versions prior to 2.8.0
Description The issue concerns a Cross-Site Request Forgery (CSRF) vulnerability in the API endpoint: /api/<method>. This vulnerability can result in Task metadata, such as task name, id, parameter, etc., being leaked to unauthorized users. The attack appears to be exploitable via a specially crafted webpage that the victim must visit from the network where their Luigi server is accessible.
Recommendations For Luigi versions prior to 2.8.0, update to version 2.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the /api/<method> API endpoint to minimize the risk of exploitation.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-1000843
GHSA-P69G-F978-XXV9
PYSEC-2018-11

Affected Products

Luigi