CVE-2018-8023
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Apache Mesos can be configured to require authentication to call the Executor HTTP API using JSON Web Token (JWT). In Apache Mesos versions pre-1.4.2, 1.5.0, 1.5.1, 1.6.0 the comparison of the generated HMAC value against the provided signature in the JWT implementation used is vulnerable to a timing attack because instead of a constant-time string comparison routine a standard `==` operator has been used. A malicious actor can therefore abuse the timing difference of when the JWT validation function returns to reveal the correct HMAC value.
Apache Mesos puede configurarse para que requiera autenticación para llamar a la API HTTP Executor utilizando JSON Web Token (JWT). En las versiones de Apache Mesos anteriores a la 1.4.2, 1.5.0, 1.5.1 y 1.6.0, la comparación del valor HMAC generado con la firma proporcionada en la implementación de JWT utilizada es vulnerable a un ataque de sincronización porque, en lugar de una rutina de comparación de cadenas de tiempo constante, se ha utilizado un operador estándar "==". Por lo tanto, un actor malicioso puede aprovecharse de la diferencia de tiempo de cuando retorna la función de validación de JWT para revelar el valor correcto de HMAC.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-03-09 CVE Reserved
- 2018-09-21 CVE Published
- 2023-03-08 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Apache Search vendor "Apache" | Mesos Search vendor "Apache" for product "Mesos" | < 1.4.2 Search vendor "Apache" for product "Mesos" and version " < 1.4.2" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Mesos Search vendor "Apache" for product "Mesos" | 1.5.0 Search vendor "Apache" for product "Mesos" and version "1.5.0" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Mesos Search vendor "Apache" for product "Mesos" | 1.5.1 Search vendor "Apache" for product "Mesos" and version "1.5.1" | - |
Affected
| ||||||
Apache Search vendor "Apache" | Mesos Search vendor "Apache" for product "Mesos" | 1.6.0 Search vendor "Apache" for product "Mesos" and version "1.6.0" | - |
Affected
|