CVE-2023-46739

Source
https://nvd.nist.gov/vuln/detail/CVE-2023-46739
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2023-46739.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2023-46739
Aliases
Related
Published
2024-01-03T17:15:10Z
Modified
2025-01-08T15:19:33.911125Z
Severity
  • 5.9 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

CubeFS is an open-source cloud-native file storage system. A vulnerability was found during in the CubeFS master component in versions prior to 3.3.1 that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root case of the vulnerability was that CubeFS used raw string comparison of passwords. The vulnerable part of CubeFS was the UserService of the master component. The UserService gets instantiated when starting the server of the master component. The issue has been patched in v3.3.1. For impacted users, there is no other way to mitigate the issue besides upgrading.

References

Affected packages

Git / github.com/cubefs/cubefs

Affected ranges

Type
GIT
Repo
https://github.com/cubefs/cubefs
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed

Affected versions

v1.*

v1.0.0
v1.1.0
v1.1.1
v1.2.0
v1.3.0
v1.4.0
v1.5.0
v1.5.1

v2.*

v2.0.0
v2.0.0-rc.1
v2.1.0
v2.1.0-rc.1
v2.2.0
v2.2.1
v2.2.2
v2.3.0-rc.1
v2.4.0-rc.0
v2.5.0-rc.0

v3.*

v3.0.0
v3.1.0
v3.1.1
v3.1.2
v3.2.0
v3.2.1
v3.3.0