VDB
Sign up
MEDIUM4.3

GHSA-992g-9cr3-vm5x

Hatchet DurableTask WorkerStatus gRPC resolves caller-supplied durable-task UUIDs via ListSatisfiedEntries with no tenant_id filter

Quick fix

GHSA-992g-9cr3-vm5x — github.com/hatchet-dev/hatchet: upgrade to the fixed version with the command below.

go get github.com/hatchet-dev/hatchet@v0.106.1

Details

# Cross-tenant disclosure risk on `DurableTask` bidi RPC

This is a low-severity, low-risk cross-tenant data exposure vuln caused by blindly accepting a durable task id, in addition to a list of node and branch ids that identify records in that task's event log, and returning them to the caller via the `handleWorkerStatus` polling path.

# Impact

This advisory requires an attacker to successfully guess a durable task's external uuid belonging to another tenant. External ids are generated uuid v4s (`uuid.New()` in Go), so exploitation requires prior knowledge of a target task UUID through an out-of-band channel. Thus, while the following environments are impacted, there is an extremely low probability it would be exploited.

### Who is impacted. Any Hatchet deployment that hosts more than one tenant on the same instance:

* Hatchet Cloud (multi-tenant SaaS) * Self-hosted Hatchet with multiple internal teams / business units sharing one instance * Any deployment where a single tenant's API token can be obtained by an attacker

Single-tenant self-hosted deployments are unaffected in practice (the "victim" and "attacker" tenants would be the same).

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/hatchet-dev/hatchet
Introduced in: 0Fixed in: 0.106.1
Fixgo get github.com/hatchet-dev/hatchet@v0.106.1

References