QID 996494
Date Published: 2024-01-04
QID 996494: GO (Go) Security Update for github.com/cubefs/cubefs (GHSA-4248-p65p-hcrm)
CubeFS used an insecure random string generator to generate user-specific, sensitive keys used to authenticate users in a CubeFS deployment. This could allow an attacker to predict and/or guess the generated string and impersonate a user thereby obtaining higher privileges.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-4248-p65p-hcrm for updates and patch information.
Vendor References
- GHSA-4248-p65p-hcrm -
github.com/advisories/GHSA-4248-p65p-hcrm
CVEs related to QID 996494
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-4248-p65p-hcrm | github.com/cubefs/cubefs |
|