GHSA-r5hm-mp3j-285g

Suggest an improvement
Source
https://github.com/advisories/GHSA-r5hm-mp3j-285g
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/09/GHSA-r5hm-mp3j-285g/GHSA-r5hm-mp3j-285g.json
JSON Data
https://api.test.osv.dev/v1/vulns/GHSA-r5hm-mp3j-285g
Aliases
Related
Published
2023-09-26T19:35:39Z
Modified
2023-11-01T05:02:59.303259Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H CVSS Calculator
Summary
sing-box vulnerable to improper authentication in the SOCKS inbound
Details

Impact

This vulnerability allows specially crafted requests to bypass authentication, affecting all SOCKS inbounds with user authentication.

Patches

Update to sing-box 1.4.5 or 1.5.0-rc.5 and later versions.

Workarounds

Don't expose the SOCKS5 inbound to insecure environments.

Database specific
{
    "nvd_published_at": "2023-09-25T20:15:11Z",
    "cwe_ids": [
        "CWE-306"
    ],
    "severity": "CRITICAL",
    "github_reviewed": true,
    "github_reviewed_at": "2023-09-26T19:35:39Z"
}
References

Affected packages

Go / github.com/sagernet/sing-box

Package

Name
github.com/sagernet/sing-box
View open source insights on deps.dev
Purl
pkg:golang/github.com/sagernet/sing-box

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.4.5

Go / github.com/sagernet/sing-box

Package

Name
github.com/sagernet/sing-box
View open source insights on deps.dev
Purl
pkg:golang/github.com/sagernet/sing-box

Affected ranges

Type
SEMVER
Events
Introduced
1.5.0-beta.1
Fixed
1.5.0-rc.5

Go / github.com/sagernet/sing

Package

Name
github.com/sagernet/sing
View open source insights on deps.dev
Purl
pkg:golang/github.com/sagernet/sing

Affected ranges

Type
SEMVER
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.2.12-0.20230925092853-5b05b5c147d9