PT-2024-13377 · Cubefs · Cubefs
Adamkorcz
·
Published
2024-01-03
·
Updated
2024-06-28
·
CVE-2023-46742
CVSS v4.0
5.1
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
CubeFS versions prior to 3.3.1
Description
CubeFS is an open-source cloud-native file storage system that was found to leak users' secret keys and access keys in the logs in multiple components. When CubeFS creates new users, it leaks the users' secret key. This could allow a lower-privileged user with access to the logs to retrieve sensitive information and impersonate other users with higher privileges than themselves. There is no evidence of this issue being exploited in the wild, and it was discovered during a security audit.
Recommendations
For CubeFS versions prior to 3.3.1, the issue can be resolved by upgrading to version 3.3.1 or later. There is no other mitigation than upgrading CubeFS.
Exploit
Fix
Insertion into Log File
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cubefs