CVE-2018-8023
published 2018-09-21CVE-2018-8023: Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0…
PriorityP335medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
3.06%
86.1th percentile
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | mesos | < 1.4.2 | 1.4.2 |
| apache | mesos | — | — |
| apache | mesos | — | — |
| apache | mesos | — | — |
| apache_software_foundation | apache_mesos | — | — |
| apache_software_foundation | apache_mesos | — | — |
| apache_software_foundation | apache_mesos | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Moderate severity vulnerability that affects org.apache.mesos:mesos
osv·2018-10-17
CVE-2018-8023 [MEDIUM] Moderate severity vulnerability that affects org.apache.mesos:mesos
Moderate severity vulnerability that affects org.apache.mesos:mesos
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
GHSA
Moderate severity vulnerability that affects org.apache.mesos:mesos
ghsa·2018-10-17
CVE-2018-8023 [MEDIUM] CWE-200 Moderate severity vulnerability that affects org.apache.mesos:mesos
Moderate severity vulnerability that affects org.apache.mesos:mesos
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
Red Hat
mesos: Exposure of HMAC value via timing vulnerability in JWT validation
vendor_redhat·2018-09-21·CVSS 5.9
CVE-2018-8023 [MEDIUM] CWE-385 mesos: Exposure of HMAC value via timing vulnerability in JWT validation
mesos: Exposure of HMAC value via timing vulnerability in JWT validation
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
Package: mesos (Red Hat Fuse 7) - Not affected
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation
bugzilla·2018-09-25·CVSS 5.9
CVE-2018-8023 [MEDIUM] CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation
CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation
Apache Mesos can be configured to require authentication to call the
Executor HTTP API using JSON Web Token (JWT). The comparison of the
generated HMAC value against the provided signature in the JWT
implementation used is vulnerable to a timing attack because instead
of a constant-time string comparison routine a standard `==` operator
has been used. A malicious actor can therefore abuse the timing
difference of when the JWT validation function returns to reveal the
correct HMAC value.
Upstream patch:
https://github.com/apache/mesos/commit/2c282f19755ea7518caf6f43e729524b1c6bdb23
References:
https://seclists.org/oss-sec/2018/q3/267
Discussion:
Created mesos tracking bugs for this issue:
Affects:
Bugzilla
CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation [fedora-all]
bugzilla·2018-09-25·CVSS 5.9
CVE-2018-8023 [MEDIUM] CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation [fedora-all]
CVE-2018-8023 mesos: Exposure of HMAC value via timing vulnerability in JWT validation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multi
https://lists.apache.org/thread.html/9b9d3f6bd09f3ebd2284b82077033bdc71da550a1c4c010c2494acc3%40%3Cdev.mesos.apache.org%3Ehttps://lists.apache.org/thread.html/r0dd7ff197b2e3bdd80a0326587ca3d0c22e10d1dba17c769d6da7d7a%40%3Cuser.flink.apache.org%3Ehttps://lists.apache.org/thread.html/9b9d3f6bd09f3ebd2284b82077033bdc71da550a1c4c010c2494acc3%40%3Cdev.mesos.apache.org%3Ehttps://lists.apache.org/thread.html/r0dd7ff197b2e3bdd80a0326587ca3d0c22e10d1dba17c769d6da7d7a%40%3Cuser.flink.apache.org%3E
2018-09-21
Published