Lucene search

K
cvelistGitHub_MCVELIST:CVE-2024-31216
HistoryMay 15, 2024 - 3:52 p.m.

CVE-2024-31216 source-controller leaks theAzure Storage SAS token into logs on connection errors

2024-05-1515:52:15
CWE-532
GitHub_M
www.cve.org
1
cve-2024-31216
source-controller
azure storage
sas token
kubernetes
artifacts acquisition
git
oci
helm repositories
s3-compatible buckets
fluxcd.io
gitops toolkit
azure blob storage
vulnerability
fix
v1.2.5
workaround
azure workload identity

5.1 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

15.5%

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. The source-controller implements the source.toolkit.fluxcd.io API and is a core component of the GitOps toolkit. Prior to version 1.2.5, when source-controller was configured to use an Azure SAS token when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires. This vulnerability was fixed in source-controller v1.2.5. There is no workaround for this vulnerability except for using a different auth mechanism such as Azure Workload Identity.

CNA Affected

[
  {
    "vendor": "fluxcd",
    "product": "source-controller",
    "versions": [
      {
        "version": "< 1.2.5",
        "status": "affected"
      }
    ]
  }
]

5.1 Medium

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

0.0004 Low

EPSS

Percentile

15.5%

Related for CVELIST:CVE-2024-31216