GHSA-v988-828w-xvf2
Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui
Quick fix
GHSA-v988-828w-xvf2 — rucio-webui: upgrade to the fixed version with the command below.
pip install --upgrade 'rucio-webui>=1.26.7'Details
### Impact `rucio-webui` installations of the `1.26` release line potentially leak the contents of cookies to other sessions within a wsgi container. Impact is that Rucio authentication tokens are leaked to other users accessing the `webui` within a close timeframe, thus allowing users to access the `webui` with the leaked authentication token. Privileges are therefore also escalated.
Rucio server / daemons are not affected by this issue, it is isolated to the webui.
### Patches This issue is fixed in the `1.26.7` release of the `rucio-webui`.
### Workarounds Installation of the `1.25.7` `webui` release. The `1.25` and previous webui release lines are not affected by this issue.
### References https://github.com/rucio/rucio/issues/4928
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/rucio/rucio/security/advisories/GHSA-v988-828w-xvf2[WEB]
- https://github.com/rucio/rucio/issues/4810[WEB]
- https://github.com/rucio/rucio/issues/4928[WEB]
- https://github.com/rucio/rucio/commit/8f832404ae88d6300e17d7e706b40fe58e0df90c[WEB]
- https://github.com/rucio/rucio[PACKAGE]
- https://github.com/rucio/rucio/releases/tag/1.26.7[WEB]