GHSA-r6v9-p59m-gj2p

    Dashboard / Vulnerabilities / GHSA-r6v9-p59m-gj2p

    GHSA-r6v9-p59m-gj2p

    Published: 2 Sept 2022Last Modified: 23 Nov 2024

    Summary: Indy's NODE_UPGRADE transaction vulnerable to remote code execution

    Details: ### Impact The `pool-upgrade` request handler in Indy-Node `<=1.12.4` allows an improperly authenticated attacker to remotely execute code on nodes within the network. Network operators are strongly encouraged to upgrade to the latest Indy-Node release `>=1.12.5` as soon as possible. ### Patches The `pool-upgrade` request handler in Indy-Node `>=1.12.5` has been updated to properly authenticate `pool-upgrade` transactions before any processing is performed by the request handler. The transactions are further sanitized to prevent remote code execution. ### Mitigations Network operators are strongly encouraged to upgrade to the latest Indy-Node release `>=1.12.5` as soon as possible. ### Acknowledgements Thank you to @shakreiner at CyberArk Labs for finding and responsibly disclosing this issue.

    Affected packages

    Package

    Name: indy-node

    Purl: pkg:pypi/indy-node

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -1.12.5rc1

    Affected versions

    0.0.1.dev38
    0.0.1.dev40
    0.0.12
    0.0.2
    0.0.20
    0.0.21
    0.0.22
    0.0.23
    0.0.24
    0.0.25
    0.0.28
    0.0.3
    0.0.30
    0.0.31
    0.0.32
    0.0.4

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-r6v9-p59m-gj2p | CVE-DB