From 3b871b7fe0d7c79923a818d05fe830c92831a300 Mon Sep 17 00:00:00 2001 From: "advisory-database[bot]" <45398580+advisory-database[bot]@users.noreply.github.com> Date: Thu, 9 Jan 2025 17:25:27 +0000 Subject: [PATCH] Publish GHSA-675f-rq2r-jw82 --- .../GHSA-675f-rq2r-jw82.json | 66 +++++++++++++++++++ 1 file changed, 66 insertions(+) create mode 100644 advisories/github-reviewed/2025/01/GHSA-675f-rq2r-jw82/GHSA-675f-rq2r-jw82.json diff --git a/advisories/github-reviewed/2025/01/GHSA-675f-rq2r-jw82/GHSA-675f-rq2r-jw82.json b/advisories/github-reviewed/2025/01/GHSA-675f-rq2r-jw82/GHSA-675f-rq2r-jw82.json new file mode 100644 index 00000000000..b1439dd675e --- /dev/null +++ b/advisories/github-reviewed/2025/01/GHSA-675f-rq2r-jw82/GHSA-675f-rq2r-jw82.json @@ -0,0 +1,66 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-675f-rq2r-jw82", + "modified": "2025-01-09T17:23:43Z", + "published": "2025-01-09T17:23:43Z", + "aliases": [ + "CVE-2025-22149" + ], + "summary": "JWK Set's HTTP client only overwrites and appends JWK to local cache during refresh", + "details": "### Impact\nThe project's provided HTTP client's local JWK Set cache should do a full replacement when the goroutine refreshes the remote JWK Set. The current behavior is to overwrite or append. This is a security issue for use cases that utilize the provided auto-caching HTTP client and where key removal from a JWK Set is equivalent to revocation.\n\nExample attack scenario:\n1. An attacker has stolen the private key for a key published in JWK Set.\n2. The publishers of that JWK Set remove that key from the JWK Set.\n3. Enough time has passed that the program using the auto-caching HTTP client found in `github.com/MicahParks/jwkset` v0.5.0-v0.5.21 has elapsed its `HTTPClientStorageOptions.RefreshInterval` duration, causing a refresh of the remote JWK Set.\n4. The attacker is signing content (such as JWTs) with the stolen private key and the system has no other forms of revocation.\n\n### Patches\nThe affected auto-caching HTTP client was added in version `v0.5.0` and fixed in `v0.6.0`. Upgrade to `v0.6.0` or later.\n\n### Workarounds\nThe only workaround would be to remove the provided auto-caching HTTP client and replace it with a custom implementation. This involves setting the `HTTPClientStorageOptions.RefreshInterval` to zero (or not specifying the value). Upgrade to `v0.6.0` is advised.\n\n### References\nPlease see the tracking issue on GitHub for additional details: https://github.com/MicahParks/jwkset/issues/40\n", + "severity": [ + { + "type": "CVSS_V4", + "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N" + } + ], + "affected": [ + { + "package": { + "ecosystem": "Go", + "name": "github.com/MicahParks/jwkset" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.5.0" + }, + { + "fixed": "0.6.0" + } + ] + } + ], + "database_specific": { + "last_known_affected_version_range": "<= 0.5.21" + } + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/MicahParks/jwkset/security/advisories/GHSA-675f-rq2r-jw82" + }, + { + "type": "WEB", + "url": "https://github.com/MicahParks/jwkset/issues/40" + }, + { + "type": "WEB", + "url": "https://github.com/MicahParks/jwkset/pull/41" + }, + { + "type": "PACKAGE", + "url": "https://github.com/MicahParks/jwkset" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "LOW", + "github_reviewed": true, + "github_reviewed_at": "2025-01-09T17:23:43Z", + "nvd_published_at": null + } +} \ No newline at end of file