diff --git a/advisories/github-reviewed/2024/12/GHSA-4fg7-vxc8-qx5w/GHSA-4fg7-vxc8-qx5w.json b/advisories/github-reviewed/2024/12/GHSA-4fg7-vxc8-qx5w/GHSA-4fg7-vxc8-qx5w.json new file mode 100644 index 00000000000..e8ddb7f21c2 --- /dev/null +++ b/advisories/github-reviewed/2024/12/GHSA-4fg7-vxc8-qx5w/GHSA-4fg7-vxc8-qx5w.json @@ -0,0 +1,281 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fg7-vxc8-qx5w", + "modified": "2024-12-18T18:21:55Z", + "published": "2024-12-18T18:21:55Z", + "aliases": [], + "summary": "rage vulnerable to malicious plugin names, recipients, or identities causing arbitrary binary execution", + "details": "A plugin name containing a path separator may allow an attacker to execute an arbitrary binary.\n\nSuch a plugin name can be provided to the `rage` CLI through an attacker-controlled recipient or identity string, or to the following `age` APIs when the `plugin` feature flag is enabled:\n- [`age::plugin::Identity::from_str`](https://docs.rs/age/0.11.0/age/plugin/struct.Identity.html#impl-FromStr-for-Identity) (or equivalently [`str::parse::()`](https://doc.rust-lang.org/stable/core/primitive.str.html#method.parse))\n- [`age::plugin::Identity::default_for_plugin`](https://docs.rs/age/0.11.0/age/plugin/struct.Identity.html#method.default_for_plugin)\n- [`age::plugin::IdentityPluginV1::new`](https://docs.rs/age/0.11.0/age/plugin/struct.IdentityPluginV1.html#method.new)\n- [`age::plugin::Recipient::from_str`](https://docs.rs/age/0.11.0/age/plugin/struct.Recipient.html#impl-FromStr-for-Recipient) (or equivalently [`str::parse::()`](https://doc.rust-lang.org/stable/core/primitive.str.html#method.parse))\n- [`age::plugin::RecipientPluginV1::new`](https://docs.rs/age/0.11.0/age/plugin/struct.RecipientPluginV1.html#method.new)\n\nOn UNIX systems, a directory matching `age-plugin-*` needs to exist in the working directory for the attack to succeed.\n\nThe binary is executed with a single flag, either `--age-plugin=recipient-v1` or `--age-plugin=identity-v1`. The standard input includes the recipient or identity string, and the random file key (if encrypting) or the header of the file (if decrypting). The format is constrained by the [age-plugin](https://c2sp.org/age-plugin) protocol.\n\nAn equivalent issue was fixed in [the reference Go implementation of age](https://github.com/FiloSottile/age), see advisory [GHSA-32gq-x56h-299c](https://github.com/FiloSottile/age/security/advisories/GHSA-32gq-x56h-299c).\n\nThanks to ⬡-49016 for reporting this issue.", + "severity": [], + "affected": [ + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.6.0" + }, + { + "fixed": "0.6.1" + } + ] + } + ], + "versions": [ + "0.6.0" + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.6.0" + }, + { + "fixed": "0.6.1" + } + ] + } + ], + "versions": [ + "0.6.0" + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.7.0" + }, + { + "fixed": "0.7.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + }, + { + "fixed": "0.8.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.0" + }, + { + "fixed": "0.9.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.10.0" + }, + { + "fixed": "0.10.1" + } + ] + } + ], + "versions": [ + "0.10.0" + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "age" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.0" + }, + { + "fixed": "0.11.1" + } + ] + } + ], + "versions": [ + "0.11.0" + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.7.0" + }, + { + "fixed": "0.7.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.8.0" + }, + { + "fixed": "0.8.2" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.9.0" + }, + { + "fixed": "0.9.3" + } + ] + } + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.10.0" + }, + { + "fixed": "0.10.1" + } + ] + } + ], + "versions": [ + "0.10.0" + ] + }, + { + "package": { + "ecosystem": "crates.io", + "name": "rage" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0.11.0" + }, + { + "fixed": "0.11.1" + } + ] + } + ], + "versions": [ + "0.11.0" + ] + } + ], + "references": [ + { + "type": "WEB", + "url": "https://github.com/str4d/rage/security/advisories/GHSA-4fg7-vxc8-qx5w" + }, + { + "type": "WEB", + "url": "https://github.com/str4d/rage/commit/703152ecfa86f27952a35b57dd525ed39396a227" + }, + { + "type": "PACKAGE", + "url": "https://github.com/str4d/rage" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-25" + ], + "severity": "MODERATE", + "github_reviewed": true, + "github_reviewed_at": "2024-12-18T18:21:55Z", + "nvd_published_at": null + } +} \ No newline at end of file