GHSA-v554-xwgw-hc3w
source-controller leaks Azure Storage SAS token into logs
Quick fix
GHSA-v554-xwgw-hc3w — github.com/fluxcd/source-controller: upgrade to the fixed version with the command below.
go get github.com/fluxcd/source-controller@v1.2.5Details
### Impact
When source-controller is configured to use an [Azure SAS token](https://v2-2.docs.fluxcd.io/flux/components/source/buckets/#azure-blob-sas-token-example) when connecting to Azure Blob Storage, the token was logged along with the Azure URL when the controller encountered a connection error. An attacker with access to the source-controller logs could use the token to gain access to the Azure Blob Storage until the token expires.
### Patches
This vulnerability was fixed in source-controller **v1.2.5**.
### Workarounds
There is no workaround for this vulnerability except for using a different auth mechanism such as [Azure Workload Identity](https://v2-2.docs.fluxcd.io/flux/components/source/buckets/#azure).
### Credits
This issue was reported and fixed by Jagpreet Singh Tamber (@jagpreetstamber) from the Azure Arc team.
### References
https://github.com/fluxcd/source-controller/pull/1430
### For more information
If you have any questions or comments about this advisory:
- Open an issue in the source-controller repository. - Contact us at the CNCF Flux Channel.
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 1.2.5go get github.com/fluxcd/source-controller@v1.2.5References
- https://github.com/fluxcd/source-controller/security/advisories/GHSA-v554-xwgw-hc3w[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-31216[ADVISORY]
- https://github.com/fluxcd/source-controller/pull/1430[WEB]
- https://github.com/fluxcd/source-controller/commit/915d1a072a4f37dd460ba33079dc094aa6e72fa9[WEB]
- https://github.com/fluxcd/source-controller[PACKAGE]