Bug 2308685 (CVE-2024-8260) - CVE-2024-8260 opa: OPA SMB Force-Authentication
Summary: CVE-2024-8260 opa: OPA SMB Force-Authentication
Keywords:
Status: NEW
Alias: CVE-2024-8260
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2308971 2308972
Blocks:
TreeView+ depends on / blocked
 
Reported: 2024-08-30 13:21 UTC by OSIDB Bzimport
Modified: 2025-03-17 23:45 UTC (History)
8 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)
PDF with API code? (108.38 KB, application/pdf)
2024-09-03 14:40 UTC, Anon
c7r8j61p: review? (bzimport)
Details

Description OSIDB Bzimport 2024-08-30 13:21:09 UTC
A SMB force-authentication vulnerability exists in all versions of OPA for Windows prior to v0.68.0. The vulnerability exists because of improper input validation, allowing a user to pass an arbitrary SMB share instead of a Rego file as an argument to OPA CLI or to one of the OPA Go library’s functions.

Comment 1 Anon 2024-09-03 14:28:39 UTC
I’ve been having security issues with my phone and my work. Going on a month now. There have been hackers putting files in my phone, and last week I found another one.It appears to be a false tax document with my name typed, and labeled with what looks an API code. I want to upload it here, I’m just not comfortable with my name on it, so I did black it out. Let me know if you need the original.

Comment 2 Anon 2024-09-03 14:40:14 UTC
Created attachment 2045297 [details]
PDF with API code?

This was in my phone along with other documents I uploaded on another ticket. I work for a large company at home, and someone would have to force authenticate to get into their system. I did not label this document, and it appears to be completely made up when I googled the info in this. There is also some kind of signature in the bottom left?


Note You need to log in before you can comment on or make changes to this bug.