PT-2021-23958 · Sourcegraph · Sourcegraph

Published

2021-12-13

·

Updated

2022-02-15

·

CVE-2021-43823

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: Sourcegraph versions prior to 3.33.2
Description: The issue allows an authenticated but unauthorized actor to guess strings in private source code through a side-channel attack. This affects the Saved Searches and Code Monitoring features. A successful attack requires creating many Saved Searches or Code Monitors to confirm the existence of a specific string, potentially allowing an attacker to guess formatted tokens like API keys.
Recommendations: For versions prior to 3.33.2, upgrade to version 3.33.2 or a later version to secure your system. If upgrading is not possible, disable Saved Searches and Code Monitors as a temporary workaround.

Fix

Information Disclosure

Side Channel Attack

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-43823
GHSA-CPQ7-HMVV-29W9

Affected Products

Sourcegraph