VDB
Sign up
CRITICAL

GHSA-622h-h2p8-743x

JWT token compromise can allow malicious actions including Remote Code Execution (RCE)

Quick fix

GHSA-622h-h2p8-743x — github.com/neuvector/neuvector: upgrade to the fixed version with the command below.

go get github.com/neuvector/neuvector@v0.0.0-20231003121714-be746957ee7c

Details

### Impact

A user can reverse engineer the JWT token (JSON Web Token) used in authentication for Manager and API access, forging a valid NeuVector Token to perform malicious activity in NeuVector. This can lead to an RCE.

### Patches

Upgrade to NeuVector [version 5.2.2](https://open-docs.neuvector.com/releasenotes/5x) or later and latest Helm chart (2.6.3+). + In 5.2.2 the certificate for JWT-signing is created automatically by controller with validity of 90days and rotated automatically. + Use Helm-based deployment/upgrade to 5.2.2 to generate a unique certificate for Manager, REST API, ahd registry adapter. Helm based installation/upgrade is required in order to automatically generate certificates upon initial installation and each subsequent upgrade. + See [release notes](https://open-docs.neuvector.com/releasenotes/5x) for manual/yaml based deployment advice. + 5.2.2 also implements additional protections against possible RCE for the feature of custom compliance scripts.

### Workarounds

Users can replace the Manager & Controller certificate manually by following the instructions in documented [here](https://open-docs.neuvector.com/configuration/console/replacecert). However, upgrading to 5.2.2 and replacing Manager/REST API certificate is recommended to provide additional security enhancements to prevent possible attempted exploit and resulting RCE. See [release notes](https://open-docs.neuvector.com/releasenotes/5x) for additional details.

### Credits

Thank you to [Dejan Zelic](https://dejandayoff.com/) at [Offensive Security](https://www.offsec.com/) for responsibly reporting this vulnerability.

### For More Information

View the NeuVector [Security Policy](https://github.com/neuvector/neuvector/security)

General NeuVector [documentation](https://open-docs.neuvector.com/)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/neuvector/neuvector
Introduced in: 0Fixed in: 0.0.0-20231003121714-be746957ee7c
Fixgo get github.com/neuvector/neuvector@v0.0.0-20231003121714-be746957ee7c

References