GHSA-w9mr-28mw-j8hg

    Dashboard / Vulnerabilities / GHSA-w9mr-28mw-j8hg

    GHSA-w9mr-28mw-j8hg

    Published: 26 Apr 2023Last Modified: 20 Aug 2024
    Aliases:

    Summary: Hop-by-hop abuse to malform header mutator

    Details: ### Impact Downstream services relying on the presence of headers set by the `header` mutator could be exploited. A client can drop the header set by the `header` mutator by including that header's name in the `Connection` header. Example minimal config: ```yaml - id: 'example' upstream: url: 'https://example.com' match: url: 'http://127.0.0.1:4455/' methods: - GET authenticators: - handler: anonymous authorizer: handler: allow mutators: - handler: header config: headers: X-Subject: {{ .Subject }} ``` ``` curl -H "Connection: close,x-subject" http://127.0.0.1:4455/ ``` The `X-Subject` header will not arrive at the downstream server. It is completely dropped. In case the downstream server handles such a request in an unexpected way, an attacker can exploit this, assuming they know or guess the internal header name. ### Patches c5cc7f736dc84185034be4356057d1c7a656d797 ### Workarounds The downstream server should handle the case that an expected header is not set by responding with an appropriate error. ### References See background info in https://github.com/golang/go/issues/50580

    Affected packages

    Package

    Name: github.com/ory/oathkeeper

    Purl: pkg:golang/github.com/ory/oathkeeper

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -0.40.3

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-w9mr-28mw-j8hg | CVE-DB