QID 981138
QID 981138: Java (maven) Security Update for org.apache.mesos:mesos (GHSA-c8cc-p3j7-4c7f)
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-c8cc-p3j7-4c7f for updates pertaining to this vulnerability.
Vendor References
- GHSA-c8cc-p3j7-4c7f -
github.com/advisories/GHSA-c8cc-p3j7-4c7f
CVEs related to QID 981138
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-c8cc-p3j7-4c7f | org.apache.mesos:mesos |
|