GHSA-3wxm-m9m4-cprj
Dashboard / Vulnerabilities / GHSA-3wxm-m9m4-cprj
Summary: Import of incorrectly embargoed keys could cause early publication
Details: ### Impact If your installation is using the `export-importer` service, there is potential impact. If your installation is not importing keys via the `export-importer` services, your installation is not impacted. In versions `0.19.1` and earlier, the `export-importer` service assumed that the server it was importing from had properly embargoed keys for at least 2 hours after their expiry time. There are now known instances of servers that did not properly embargo keys. This could allow allow for imported keys to be re-published before they have expired, allowing for potential replay of RPIs. ### Patches This is patched in `v0.18.3` and all versions `0.19.2` and later. ### Workarounds Ensure that the servers you are importing export zip files from are not publishing keys too early. ### References n/a ### For more information If you have any questions or comments about this advisory * Open an issue in [exposure-notifications-server](https://github.com/google/exposure-notifications-server/) * Email us at [[email protected]](mailto:[email protected])
References: https://github.com/google/exposure-notifications-server/security/advisories/GHSA-3wxm-m9m4-cprj
Affected packages
Package
Name: github.com/google/exposure-notifications-server
Purl: pkg:golang/github.com/google/exposure-notifications-server
Affected ranges
Type: SEMVER
Events:
