PT-2024-13374 · Cubefs · Cubefs
Adamkorcz
·
Published
2024-01-03
·
Updated
2024-06-28
·
CVE-2023-46739
CVSS v4.0
8.2
High
| Vector | AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:L |
Name of the Vulnerable Software and Affected Versions
CubeFS versions prior to 3.3.1
Description
A vulnerability was found in the CubeFS master component that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root cause of the issue was that CubeFS used raw string comparison of passwords. The vulnerable part of CubeFS was the UserService of the master component, which gets instantiated when starting the server of the master component. There is no evidence of this vulnerability being exploited in the wild. The issue was discovered during a security audit.
Recommendations
For versions prior to 3.3.1, update to version 3.3.1 or later to resolve the issue. As a temporary workaround, consider disabling the UserService function until a patch is available. Restrict access to the master component to minimize the risk of exploitation. Avoid using the UserService until the issue is resolved.
Exploit
Fix
Side Channel Attack
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubefs