← volver
CVE-2023-46740

Insecure random string generator used for sensitive data

CVSS 6.5 MEDIUMEPSS 0.4%CWE-330
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 6.5EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
03 ene 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
CubeFS is an open-source cloud-native file storage system. Prior to version 3.3.1, CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a user thereby obtaining higher privileges. When CubeFS creates new users, it creates a piece of sensitive information for the user called the “accessKey”. To create the "accesKey", CubeFS uses an insecure string generator which makes it easy to guess and thereby impersonate the created user. An attacker could leverage the predictable random string generator and guess a users access key and impersonate the user to obtain higher privileges. The issue has been fixed in v3.3.1. There is no other mitigation than to upgrade.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L
Productos afectados
cubefs · cubefs

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →