Information Exposure Affecting github.com/cubefs/cubefs/blobstore/access package, versions <3.3.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.1% (42nd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMCUBEFSCUBEFSBLOBSTOREACCESS-6143560
  • published4 Jan 2024
  • disclosed3 Jan 2024
  • creditAdamKorcz

Introduced: 3 Jan 2024

CVE-2023-46741  (opens in a new tab)
CWE-200  (opens in a new tab)

How to fix?

Upgrade github.com/cubefs/cubefs/blobstore/access to version 3.3.1 or higher.

Overview

Affected versions of this package are vulnerable to Information Exposure due to configuration keys being leaked in plaintext in the logs. An attacker that has successfully retrieved a secret key from the logs can delete blogs from the blob store or read sensitive data from the logs and escalate privileges.

Note: The attacker can either be an internal user with limited privileges to read the log, or it can be an external user who has escalated privileges sufficiently to access the logs.

CVSS Scores

version 3.1