Lucene search

K
githubGitHub Advisory DatabaseGHSA-J72F-H752-MX4W
HistoryNov 23, 2023 - 12:28 a.m.

Insertion of Sensitive Information into Log

2023-11-2300:28:13
CWE-532
GitHub Advisory Database
github.com
12
sensitive information exposure
log recording
raw tokens
successful login attempts
upgrade
shield
disable logging
configuration files
accesstokens
jwt
hmacsha256
authenticators
upgrade
patches
workarounds

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.3%

Impact

If successful login attempts are recorded, the raw tokens are stored in the log table.
If a malicious person somehow views the data in the log table, he or she can obtain a raw token, which can then be used to send a request with that user’s authority.

When you (1) use the following authentiactors,

and you (2) log successful login attempts, the raw tokens are stored.

Patches

Upgrade to Shield v1.0.0-beta.8 or later.

Workarounds

Disable logging for successful login attempts by the configuration files.

  • AccessTokens or HmacSha256
    • Set Config\AuthToken::$recordLoginAttempt to Auth::RECORD_LOGIN_ATTEMPT_FAILURE or Auth::RECORD_LOGIN_ATTEMPT_NONE
  • JWT
    • Set Config\AuthJWT::$recordLoginAttempt to Auth::RECORD_LOGIN_ATTEMPT_FAILURE or Auth::RECORD_LOGIN_ATTEMPT_NONE

References

For more information

If you have any questions or comments about this advisory:

Affected configurations

Vulners
Node
codeigniter4shieldRange<1.0.0-beta.8
VendorProductVersionCPE
codeigniter4shield*cpe:2.3:a:codeigniter4:shield:*:*:*:*:*:*:*:*

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

6.8

Confidence

High

EPSS

0.001

Percentile

41.3%

Related for GHSA-J72F-H752-MX4W