QID 981138

QID 981138: Java (maven) Security Update for org.apache.mesos:mesos (GHSA-c8cc-p3j7-4c7f)

Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.

Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.

  • CVSS V3 rated as Medium - 5.9 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Customers are advised to refer to GHSA-c8cc-p3j7-4c7f for updates pertaining to this vulnerability.
    Vendor References

    CVEs related to QID 981138

    Software Advisories
    Advisory ID Software Component Link
    GHSA-c8cc-p3j7-4c7f org.apache.mesos:mesos URL Logo github.com/advisories/GHSA-c8cc-p3j7-4c7f