QID 996493
Date Published: 2024-01-04
QID 996493: GO (Go) Security Update for github.com/cubefs/cubefs (GHSA-vwch-g97w-hfg2)
CubeFS was found to leak users secret keys and access keys in the logs in multiple components. When CubeCS creates new users, it leaks the users secret key. This could allow a lower-privileged user with access to the logs to retrieve sensitive information and impersonate other users with higher privileges than themselves.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vwch-g97w-hfg2 for updates and patch information.
Vendor References
- GHSA-vwch-g97w-hfg2 -
github.com/advisories/GHSA-vwch-g97w-hfg2
CVEs related to QID 996493
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwch-g97w-hfg2 | github.com/cubefs/cubefs |
|