Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.
The Dragonfly system uses JWT tokens to verify user identity. The secret key used to sign and verify these tokens is hard-coded in the application's source code. Since the key is known and immutable, an attacker can independently generate a properly signed JWT token with arbitrary privileges. As a result, the authentication mechanism can be completely bypassed without possessing any credentials.
A remote unauthenticated attacker can perform arbitrary actions with administrator privileges, leading to complete breach of confidentiality, integrity, and availability of the system.
Dragonfly2 should be immediately updated to version 2.0.9 or later. The manufacturer does not indicate any known workarounds for this vulnerability. Patch available at: https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9
Dragonfly2 (dragonflyoss/Dragonfly2) — all versions before 2.0.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HLinuxfoundation Dragonfly
APPLinuxfoundation< 2.0.9
Related vulnerabilities
Dragonfly is an open source P2P-based file distribution and image acceleration system. In versions 2.4.1-rc.0 ...
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, a peer ...
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, The /ap...
Dragonfly is an open source P2P-based file distribution and image acceleration system. Versions prior to 2.1.0...
Dragonfly is an open source P2P-based file distribution and image acceleration system. Prior to 2.1.0, the pro...