PT-2021-23971 · Unknown · Message Bus
Sam Saffron
·
Published
2021-12-17
·
Updated
2021-12-29
·
CVE-2021-43840
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
message bus versions prior to 3.3.7
Description:
The issue is a path traversal bug that could lead to disclosure of secret information on a machine if an unintended user were to gain access to the diagnostic route. This bug affects deployments with diagnostics features enabled, which is default off. The impact is greater if there is no proxy for the web application, as the number of steps up the directories is not bounded. For deployments using a proxy, the impact varies. For example, if a request goes through a proxy like Nginx with
merge slashes enabled, the number of steps up the directories that can be read is limited to 3 levels.Recommendations:
For versions prior to 3.3.7, update to version 3.3.7 to resolve the issue.
As a temporary workaround, consider disabling MessageBus::Diagnostics in production-like environments until a patch is applied.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Message Bus