QID 996501
Date Published: 2024-01-04
QID 996501: GO (Go) Security Update for github.com/cubefs/cubefs (GHSA-8579-7p32-f398)
A vulnerability was found during in the CubeFS master component that could allow an untrusted attacker to steal user passwords by carrying out a timing attack. The root case of the vulnerability was that CubeFS used raw string comparison of passwords.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8579-7p32-f398 for updates and patch information.
Vendor References
- GHSA-8579-7p32-f398 -
github.com/advisories/GHSA-8579-7p32-f398
CVEs related to QID 996501
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8579-7p32-f398 | github.com/cubefs/cubefs |
|