PT-2024-13373 · Cubefs · Cubefs
Adamkorcz
·
Published
2024-01-03
·
Updated
2024-06-28
·
CVE-2023-46738
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CubeFS versions prior to 3.3.1
Description
A security issue was found in CubeFS HandlerNode that could allow authenticated users to send maliciously-crafted requests, crashing the ObjectNode and denying other users from using it. The root cause was improper handling of incoming HTTP requests, allowing an attacker to control the amount of memory the ObjectNode would allocate. A malicious request could exhaust the machine's memory. An attacker would need to be authenticated, have permissions to delete objects, and know the names of existing buckets in the CubeFS deployment. The most likely attacker is an inside user or an attacker who has breached an existing user's account in the cluster. There is no evidence of this attack being exploited in the wild.
Recommendations
For CubeFS versions prior to 3.3.1, the issue has been patched in version 3.3.1, so upgrading to this version or later is the recommended mitigation. There is no other mitigation besides upgrading.
Exploit
Fix
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubefs