CVE-2019-7628
published 2019-02-08CVE-2019-7628: Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these…
PriorityP430medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
0.90%
55.6th percentile
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pagure | — | — |
| redhat | pagure | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vendor_debian5.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6r84-2x5x-qp36: Pagure 5
ghsa_unreviewed·2022-05-14
CVE-2019-7628 [MEDIUM] CWE-200 GHSA-6r84-2x5x-qp36: Pagure 5
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)
Debian
CVE-2019-7628: pagure - Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validat...
vendor_debian·2019·CVSS 5.9
CVE-2019-7628 [MEDIUM] CVE-2019-7628: pagure - Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validat...
Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)
Scope: local
bullseye: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2019-7628 pagure: version 5.2 leaks API keys by e-mail
bugzilla·2019-02-08·CVSS 5.9
CVE-2019-7628 [MEDIUM] CVE-2019-7628 pagure: version 5.2 leaks API keys by e-mail
CVE-2019-7628 pagure: version 5.2 leaks API keys by e-mail
It was discovered that Pagure[4] sends full API tokens in e-mails
that are intended to remind users that the tokens are expiring soon[3].
The vulnerability was introduced in 5.2[0]. There was a partial fix
applied in [1], but that fix still leaked partial keys.
At the time of this writing, a fix is proposed at [2].
There is not yet a released version of Pagure with a fix, but Pagure
administrators can work around this issue by disabling the cron job. It
may be wise to delete all API tokens that may have been e-mailed after
disabling the cron job as a precautionary measure.
[0] https://pagure.io/pagure/c/57975ef30641907947038b608017a9b721eb33fe
[1] https://pagure.io/pagure/c/9905fb1e64341822366b6ab1d414d2baa230af0a
[2] https://
Bugzilla
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [epel-7]
bugzilla·2019-02-08·CVSS 5.9
CVE-2019-7628 [MEDIUM] CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [epel-7]
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [epel-7]
+++ This bug was initially created as a clone of Bug #1673983 +++
It was discovered that Pagure[4] sends full API tokens in e-mails
that are intended to remind users that the tokens are expiring soon[3].
The vulnerability was introduced in 5.2[0]. There was a partial fix
applied in [1], but that fix still leaked partial keys.
At the time of this writing, a fix is proposed at [2].
There is not yet a released version of Pagure with a fix, but Pagure
administrators can work around this issue by disabling the cron job. It
may be wise to delete all API tokens that may have been e-mailed after
disabling the cron job as a precautionary measure.
[0] https://pagure.io/pagure/c/57975ef30641907947038b608017a9b721eb33fe
[1] http
Bugzilla
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-rawhide]
bugzilla·2019-02-08·CVSS 5.9
CVE-2019-7628 [MEDIUM] CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-rawhide]
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-rawhide]
+++ This bug was initially created as a clone of Bug #1673983 +++
It was discovered that Pagure[4] sends full API tokens in e-mails
that are intended to remind users that the tokens are expiring soon[3].
The vulnerability was introduced in 5.2[0]. There was a partial fix
applied in [1], but that fix still leaked partial keys.
At the time of this writing, a fix is proposed at [2].
There is not yet a released version of Pagure with a fix, but Pagure
administrators can work around this issue by disabling the cron job. It
may be wise to delete all API tokens that may have been e-mailed after
disabling the cron job as a precautionary measure.
[0] https://pagure.io/pagure/c/57975ef30641907947038b608017a9b721eb33fe
Bugzilla
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-29]
bugzilla·2019-02-08·CVSS 5.9
CVE-2019-7628 [MEDIUM] CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-29]
CVE-2019-7628: Pagure version 5.2 leaks API keys by e-mail [fedora-29]
+++ This bug was initially created as a clone of Bug #1673983 +++
It was discovered that Pagure[4] sends full API tokens in e-mails
that are intended to remind users that the tokens are expiring soon[3].
The vulnerability was introduced in 5.2[0]. There was a partial fix
applied in [1], but that fix still leaked partial keys.
At the time of this writing, a fix is proposed at [2].
There is not yet a released version of Pagure with a fix, but Pagure
administrators can work around this issue by disabling the cron job. It
may be wise to delete all API tokens that may have been e-mailed after
disabling the cron job as a precautionary measure.
[0] https://pagure.io/pagure/c/57975ef30641907947038b608017a9b721eb33fe
[1] h
https://pagure.io/pagure/c/9905fb1e64341822366b6ab1d414d2baa230af0ahttps://pagure.io/pagure/issue/4230https://pagure.io/pagure/issue/4252https://pagure.io/pagure/issue/4253https://pagure.io/pagure/pull-request/4254https://pagure.io/pagure/c/9905fb1e64341822366b6ab1d414d2baa230af0ahttps://pagure.io/pagure/issue/4230https://pagure.io/pagure/issue/4252https://pagure.io/pagure/issue/4253https://pagure.io/pagure/pull-request/4254
2019-02-08
Published