VDB
Sign up
MEDIUM5.1

GHSA-v554-xwgw-hc3w

source-controller leaks Azure Storage SAS token into logs

Quick fix

GHSA-v554-xwgw-hc3w — github.com/fluxcd/source-controller: upgrade to the fixed version with the command below.

go get github.com/fluxcd/source-controller@v1.2.5

Details

### Impact

When source-controller is configured to use an [Azure SAS token](https://v2-2.docs.fluxcd.io/flux/components/source/buckets/#azure-blob-sas-token-example) when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires.

### Patches

This vulnerability was fixed in source-controller **v1.2.5**.

### Workarounds

There is no workaround for this vulnerability except for using a different auth mechanism such as [Azure Workload Identity](https://v2-2.docs.fluxcd.io/flux/components/source/buckets/#azure).

### Credits

This issue was reported and fixed by Jagpreet Singh Tamber (@jagpreetstamber) from the Azure Arc team.

### References

https://github.com/fluxcd/source-controller/pull/1430

### For more information

If you have any questions or comments about this advisory:

- Open an issue in the source-controller repository. - Contact us at the CNCF Flux Channel.

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/fluxcd/source-controller
Introduced in: 0Fixed in: 1.2.5
Fixgo get github.com/fluxcd/source-controller@v1.2.5

References