PT-2024-29655 · Unknown · Biscuit-Java

·

CVE-2024-41948

·

Published

2024-07-31

·

Updated

2024-08-09

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions biscuit-java versions prior to 4.0.0
Description The issue concerns the generation of third-party blocks for authentication and authorization tokens in microservices architectures. A malicious user can forge a third-party block request, tricking the third-party authority into generating datalog that trusts the wrong keypair. This can be achieved by altering the public keys field in the ThirdPartyBlockRequest and replacing the actual public key with a different one, allowing the attacker to use the token without obtaining a third-party block from the intended authority.
Recommendations For biscuit-java versions prior to 4.0.0, upgrade to version 4.0.0 to fix the issue. As a temporary workaround, consider restricting the use of third-party block requests until the patch is applied. Avoid using altered symbol tables in ThirdPartyBlockRequest to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-41948
GHSA-5HCJ-RWM6-XMW4

Affected Products

Biscuit-Java