PT-2021-17248 · Spire · Spire
C53Robin
·
Published
2021-03-05
·
Updated
2021-03-16
·
CVE-2021-27099
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
SPIRE versions prior to 0.8.5
SPIRE versions prior to 0.9.4
SPIRE versions prior to 0.10.2
SPIRE versions prior to 0.11.3
SPIRE versions prior to 0.12.1
Description:
The issue arises from the improper normalization of the path provided through the agent ID templating feature by the "aws iid" Node Attestor. This may allow the issuance of an arbitrary SPIFFE ID within the same trust domain if the attacker controls the value of an EC2 tag prior to attestation and the attestor is configured for agent ID templating where the tag value is the last element in the path.
Recommendations:
For SPIRE versions prior to 0.8.5, update to version 0.8.5 or later.
For SPIRE versions prior to 0.9.4, update to version 0.9.4 or later.
For SPIRE versions prior to 0.10.2, update to version 0.10.2 or later.
For SPIRE versions prior to 0.11.3, update to version 0.11.3 or later.
For SPIRE versions prior to 0.12.1, update to version 0.12.1 or later.
Fix
Incorrect Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Spire