Bug 2308685 (CVE-2024-8260)

Summary: CVE-2024-8260 opa: OPA SMB Force-Authentication
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: agarcial, aoconnor, asegurap, c7r8j61p, chazlett, jburrell, jcantril, mwringe
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: If docs needed, set a value
Doc Text:
An SMB force-authentication vulnerability exists in all versions of OPA. The vulnerability exists due to improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or one of the OPA Go library’s functions.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2308971, 2308972    
Bug Blocks:    
Attachments:
Description Flags
PDF with API code? c7r8j61p: review? (bzimport)

Description OSIDB Bzimport 2024-08-30 13:21:09 UTC
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.

Comment 1 Anon 2024-09-03 14:28:39 UTC
I’ve been having security issues with my phone and my work. Going on a month now. There have been hackers putting files in my phone, and last week I found another one.It appears to be a false tax document with my name typed, and labeled with what looks an API code. I want to upload it here, I’m just not comfortable with my name on it, so I did black it out. Let me know if you need the original.

Comment 2 Anon 2024-09-03 14:40:14 UTC
Created attachment 2045297 [details]
PDF with API code?

This was in my phone along with other documents I uploaded on another ticket. I work for a large company at home, and someone would have to force authenticate to get into their system. I did not label this document, and it appears to be completely made up when I googled the info in this. There is also some kind of signature in the bottom left?