GHSA-992g-9cr3-vm5x
Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter
Quick fix
GHSA-992g-9cr3-vm5x — github.com/hatchet-dev/hatchet: upgrade to the fixed version with the command below.
go get github.com/hatchet-dev/hatchet@v0.106.1Details
# Cross-tenant disclosure risk on `DurableTask` bidi RPC
This is a low-severity, low-risk cross-tenant data exposure vuln caused by blindly accepting a durable task id, in addition to a list of node and branch ids that identify records in that task's event log, and returning them to the caller via the `handleWorkerStatus` polling path.
# Impact
This advisory requires an attacker to successfully guess a durable task's external uuid belonging to another tenant. External ids are generated uuid v4s (`uuid.New()` in Go), so exploitation requires prior knowledge of a target task UUID through an out-of-band channel. Thus, while the following environments are impacted, there is an extremely low probability it would be exploited.
### Who is impacted. Any Hatchet deployment that hosts more than one tenant on the same instance:
* Hatchet Cloud (multi-tenant SaaS) * Self-hosted Hatchet with multiple internal teams / business units sharing one instance * Any deployment where a single tenant's API token can be obtained by an attacker
Single-tenant self-hosted deployments are unaffected in practice (the "victim" and "attacker" tenants would be the same).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.106.1go get github.com/hatchet-dev/hatchet@v0.106.1