PT-2024-13373 · Cubefs · Cubefs

Adamkorcz

·

Published

2024-01-03

·

Updated

2024-06-28

·

CVE-2023-46738

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CubeFS versions prior to 3.3.1
Description A security issue was found in CubeFS HandlerNode that could allow authenticated users to send maliciously-crafted requests, crashing the ObjectNode and denying other users from using it. The root cause was improper handling of incoming HTTP requests, allowing an attacker to control the amount of memory the ObjectNode would allocate. A malicious request could exhaust the machine's memory. An attacker would need to be authenticated, have permissions to delete objects, and know the names of existing buckets in the CubeFS deployment. The most likely attacker is an inside user or an attacker who has breached an existing user's account in the cluster. There is no evidence of this attack being exploited in the wild.
Recommendations For CubeFS versions prior to 3.3.1, the issue has been patched in version 3.3.1, so upgrading to this version or later is the recommended mitigation. There is no other mitigation besides upgrading.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46738
GHSA-QC6V-G3XW-GRMX
GO-2024-2430

Affected Products

Cubefs