Bug 2255204 (CVE-2023-6944) - CVE-2023-6944 RHDH: catalog-import function leaks credentials to frontend
Summary: CVE-2023-6944 RHDH: catalog-import function leaks credentials to frontend
Keywords:
Status: NEW
Alias: CVE-2023-6944
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
: 2260001 (view as bug list)
Depends On:
Blocks: 2255205
TreeView+ depends on / blocked
 
Reported: 2023-12-19 10:23 UTC by Mauro Matteo Cascella
Modified: 2024-03-22 20:52 UTC (History)
7 users (show)

Fixed In Version: rhdh 1.21.0
Doc Type: ---
Doc Text:
A flaw was found in the Red Hat Developer Hub (RHDH). The catalog-import function leaks GitLab access tokens on the frontend when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error can display on the frontend, including the raw access token. Upon gaining access to this token and depending on permissions, an attacker could push malicious code to repositories, delete resources in Git, revoke or generate new keys, and sign code illegitimately.
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description Mauro Matteo Cascella 2023-12-19 10:23:14 UTC
A flaw was found in Red Hat Developer Hub (RHDH) in the catalog-import function. The vulnerability is that the catalog-import function leaks GitLab access tokens on the frontend. This leakage occurs when the base64 encoded GitLab token includes a newline at the end of the string. The sanitized error displayed on the frontend inadvertently includes the raw access token, which should never be exposed to frontend users.

The impact of this vulnerability is significant. An attacker, upon gaining access to this token, could potentially execute a range of malicious activities depending on the token's permissions. These activities could include pushing malicious code to repositories, deleting resources in Git, revoking or generating new keys, or even signing code illegitimately.

Comment 2 Mauro Matteo Cascella 2023-12-19 10:25:04 UTC
Red Hat Product Security would like to thank Josephine Pfeiffer for reporting this issue.

Comment 5 Mauro Matteo Cascella 2024-02-01 10:11:15 UTC
*** Bug 2260001 has been marked as a duplicate of this bug. ***


Note You need to log in before you can comment on or make changes to this bug.