GHSA-x5c7-x7m2-rhmf

    Dashboard / Vulnerabilities / GHSA-x5c7-x7m2-rhmf

    GHSA-x5c7-x7m2-rhmf

    Published: 20 May 2021Last Modified: 21 Aug 2024
    Aliases:

    Summary: Local directory executable lookup in sops (Windows-only)

    Details: ### Impact Windows users using the sops direct editor option (`sops file.yaml`) can have a local executable named either `vi`, `vim`, or `nano` executed if running sops from `cmd.exe` This attack is only viable if an attacker is able to place a malicious binary within the directory you are running sops from. As well, this attack will only work when using `cmd.exe` or the Windows C library [SearchPath function](https://docs.microsoft.com/en-us/windows/win32/api/processenv/nf-processenv-searchpatha). This is a result of these Windows tools including `.` within their `PATH` by default. **If you are using sops within untrusted directories on Windows via `cmd.exe`, please upgrade immediately** **As well, if you have `.` within your default $PATH, please upgrade immediately.** More information can be found on the official Go blog: https://blog.golang.org/path-security ### Patches The problem has been resolved in v3.7.1 Now, if Windows users using cmd.exe run into this issue, a warning message will be printed: `vim resolves to executable in current directory (.\vim.exe)` ### References * https://blog.golang.org/path-security ### For more information If you have any questions or comments about this advisory: * Open a discussion in [sops](https://github.com/mozilla/sops/discussions)

    Affected packages

    Package

    Name: go.mozilla.org/sops/v3

    Purl: pkg:golang/go.mozilla.org/sops/v3

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -3.7.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-x5c7-x7m2-rhmf | CVE-DB