GHSA-3wxm-m9m4-cprj

    Dashboard / Vulnerabilities / GHSA-3wxm-m9m4-cprj

    GHSA-3wxm-m9m4-cprj

    Published: 21 May 2021Last Modified: 21 Aug 2024
    Aliases:

    Summary: Import of incorrectly embargoed keys could cause early publication

    Details: ### Impact If your installation is using the `export-importer` service, there is potential impact. If your installation is not importing keys via the `export-importer` services, your installation is not impacted. In versions `0.19.1` and earlier, the `export-importer` service assumed that the server it was importing from had properly embargoed keys for at least 2 hours after their expiry time. There are now known instances of servers that did not properly embargo keys. This could allow allow for imported keys to be re-published before they have expired, allowing for potential replay of RPIs. ### Patches This is patched in `v0.18.3` and all versions `0.19.2` and later. ### Workarounds Ensure that the servers you are importing export zip files from are not publishing keys too early. ### References n/a ### For more information If you have any questions or comments about this advisory * Open an issue in [exposure-notifications-server](https://github.com/google/exposure-notifications-server/) * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: github.com/google/exposure-notifications-server

    Purl: pkg:golang/github.com/google/exposure-notifications-server

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.18.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3wxm-m9m4-cprj | CVE-DB