PT-2024-13377 · Cubefs · Cubefs

Adamkorcz

·

Published

2024-01-03

·

Updated

2024-06-28

·

CVE-2023-46742

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions CubeFS versions prior to 3.3.1
Description CubeFS is an open-source cloud-native file storage system that was found to leak users' secret keys and access keys in the logs in multiple components. When CubeFS creates new users, it leaks the users' secret key. This could allow a lower-privileged user with access to the logs to retrieve sensitive information and impersonate other users with higher privileges than themselves. There is no evidence of this issue being exploited in the wild, and it was discovered during a security audit.
Recommendations For CubeFS versions prior to 3.3.1, the issue can be resolved by upgrading to version 3.3.1 or later. There is no other mitigation than upgrading CubeFS.

Exploit

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-46742
GHSA-VWCH-G97W-HFG2
GO-2024-2434

Affected Products

Cubefs