CVE-2023-27584

Dragonfly is an open source P2P-based file distribution and image acceleration system. It is hosted by the Cloud Native Computing Foundation (CNCF) as an Incubating Level Project. Dragonfly uses JWT to verify user. However, the secret key for JWT, "Secret Key", is hard coded, which leads to authentication bypass. An attacker can perform any action as a user with admin privileges. This issue has been addressed in release version 2.0.9. All users are advised to upgrade. There are no known workarounds for this vulnerability.
Configurations

Configuration 1 (hide)

cpe:2.3:a:d7y:dragonfly:*:*:*:*:*:go:*:*

History

25 Sep 2024, 17:28

Type Values Removed Values Added
CWE CWE-798
First Time D7y dragonfly
D7y
References () https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9 - () https://github.com/dragonflyoss/Dragonfly2/releases/tag/v2.0.9 - Release Notes
References () https://github.com/dragonflyoss/Dragonfly2/security/advisories/GHSA-hpc8-7wpm-889w - () https://github.com/dragonflyoss/Dragonfly2/security/advisories/GHSA-hpc8-7wpm-889w - Exploit, Vendor Advisory
CPE cpe:2.3:a:d7y:dragonfly:*:*:*:*:*:go:*:*

20 Sep 2024, 12:30

Type Values Removed Values Added
Summary
  • (es) Dragonfly es un sistema de distribución de archivos y aceleración de imágenes basado en P2P de código abierto. Está alojado por la Cloud Native Computing Foundation (CNCF) como un proyecto de nivel de incubación. Dragonfly utiliza JWT para verificar al usuario. Sin embargo, la clave secreta para JWT, "Clave secreta", está codificada de forma rígida, lo que permite eludir la autenticación. Un atacante puede realizar cualquier acción como usuario con privilegios de administrador. Este problema se ha solucionado en la versión 2.0.9. Se recomienda a todos los usuarios que actualicen. No existen workarounds conocidas para esta vulnerabilidad.

19 Sep 2024, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-19 23:15

Updated : 2024-09-25 17:28


NVD link : CVE-2023-27584

Mitre link : CVE-2023-27584

CVE.ORG link : CVE-2023-27584


JSON object : View

Products Affected

d7y

  • dragonfly
CWE
CWE-798

Use of Hard-coded Credentials

CWE-321

Use of Hard-coded Cryptographic Key