VDB
Sign up
CRITICAL9.8

GHSA-mm6v-68qp-f9fw

Crayfish allows Remote Code Execution via Homarus Authorization header

Quick fix

GHSA-mm6v-68qp-f9fw — islandora/crayfish: upgrade to the fixed version with the command below.

composer require islandora/crayfish:^4.1.0

Details

### Impact

Remote code execution may be possible in web-accessible installations of Homarus in certain configurations.

### Patches

The issue has been patched in `islandora/crayfish:4.1.0`

### Workarounds

The exploit requires making a request against the Homarus's `/convert` endpoint; therefore, the ability to exploit is much reduced if the microservice is not directly accessible from the Internet, so: Prevent general access from the Internet from hitting Homarus.

Configure auth in Crayfish to be more strongly required, such that requests with `Authorization` headers that do not validate are rejected before the problematic CLI interpolation occurs.

### References

- XBOW-024-071

Are you affected?

Enter the version of the package you're using.

Affected packages

Packagist/islandora/crayfish
Introduced in: 0Fixed in: 4.1.0
Fixcomposer require islandora/crayfish:^4.1.0

References