GHSA-3wxm-m9m4-cprj
Import of incorrectly embargoed keys could cause early publication
Quick fix
GHSA-3wxm-m9m4-cprj — github.com/google/exposure-notifications-server: upgrade to the fixed version with the command below.
go get github.com/google/exposure-notifications-server@v0.18.3Details
### Impact
If your installation is using the `export-importer` service, there is potential impact. If your installation is not importing keys via the `export-importer` services, your installation is not impacted.
In versions `0.19.1` and earlier, the `export-importer` service assumed that the server it was importing from had properly embargoed keys for at least 2 hours after their expiry time. There are now known instances of servers that did not properly embargo keys.
This could allow allow for imported keys to be re-published before they have expired, allowing for potential replay of RPIs.
### Patches
This is patched in `v0.18.3` and all versions `0.19.2` and later.
### Workarounds
Ensure that the servers you are importing export zip files from are not publishing keys too early.
### References
n/a
### For more information
If you have any questions or comments about this advisory * Open an issue in [exposure-notifications-server](https://github.com/google/exposure-notifications-server/) * Email us at [exposure-notifications-feedback@google.com](mailto:exposure-notifications-feedback@google.com)
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 0.18.3go get github.com/google/exposure-notifications-server@v0.18.30.19.0Fixed in: 0.19.2go get github.com/google/exposure-notifications-server@v0.19.2