W DataHub przed wersją 0.8.45 serwis GMS nie weryfikuje podpisu kryptograficznego tokenów JWT, co pozwala atakującemu na uwierzytelnienie się jako dowolny użytkownik. Podatność jest krytyczna, ponieważ nie wymaga żadnych uprawnień ani interakcji użytkownika.
▸ Pokaż oryginał (EN)
DataHub is an open-source metadata platform. Prior to version 0.8.45, the `StatelessTokenService` of the DataHub metadata service (GMS) does not verify the signature of JWT tokens. This allows an attacker to connect to DataHub instances as any user if Metadata Service authentication is enabled. This vulnerability occurs because the `StatelessTokenService` of the Metadata service uses the `parse` method of `io.jsonwebtoken.JwtParser`, which does not perform a verification of the cryptographic token signature. This means that JWTs are accepted regardless of the used algorithm. This issue may lead to an authentication bypass. Version 0.8.45 contains a patch for the issue. There are no known workarounds.
Komponent `StatelessTokenService` w DataHub Metadata Service (GMS) używa metody `parse` biblioteki `io.jsonwebtoken.JwtParser` zamiast metody weryfikującej podpis kryptograficzny. W efekcie tokeny JWT są akceptowane bez względu na zastosowany algorytm podpisywania lub jego poprawność. Atakujący może spreparować dowolny token JWT, podając w nim tożsamość wybranego użytkownika, i uzyskać dostęp do instancji DataHub bez znajomości klucza podpisującego. Warunkiem koniecznym jest włączone uwierzytelnianie Metadata Service.
Atakujący może uzyskać nieautoryzowany dostęp do DataHub jako dowolny użytkownik, w tym jako administrator, co skutkuje pełnym przejęciem kontroli nad platformą metadanych i jej zawartością.
Należy zaktualizować DataHub do wersji 0.8.45 lub nowszej, która zawiera patch eliminujący podatność. Producent nie wskazuje żadnych znanych obejść (workarounds).
DataHub (datahub-project/datahub) we wszystkich wersjach przed 0.8.45, gdy włączone jest uwierzytelnianie Metadata Service (GMS).
Podatność została ujawniona 2022-10-28. Producent potwierdził brak jakichkolwiek znanych workaroundów — jedyną skuteczną mitygacją jest aktualizacja do wersji 0.8.45.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:LDatahub
APPDatahub< 0.8.45
Powiązane podatności
DataHub is an open-source metadata platform. Prior to version 1.3.1.8, the LDAP ingestion source is vulnerable...
DataHub is an open-source metadata platform. The AuthServiceClient which is responsible for creation of new ac...
DataHub is an open-source metadata platform. The DataHub frontend acts as a proxy able to forward any REST or ...
DataHub is an open-source metadata platform. When not using authentication for the metadata service, which is ...
DataHub to open-source'owa platforma metadanych. Przed wersją 1.5.0.3 frontend DataHub (datahub-frontend-react...