golang / vulndb

[mirror] The Go Vulnerability Database
Other
564 stars 61 forks source link

x/vulndb: potential Go vuln in go.thethings.network/lorawan-stack/v3: GHSA-5fwq-9x7j-2qpg #3044

Closed GoVulnBot closed 3 months ago

GoVulnBot commented 3 months ago

Advisory GHSA-5fwq-9x7j-2qpg references a vulnerability in the following Go modules:

Module
go.thethings.network/lorawan-stack
go.thethings.network/lorawan-stack/v3

Description: lorawan-stack is an open source LoRaWAN network server. Prior to version 3.24.1, an open redirect exists on the login page of the lorawan stack server, allowing an attacker to supply a user controlled redirect upon sign in. This issue may allows malicious actors to phish users, as users assume they were redirected to the homepage on login. Version 3.24.1 contains a fix.

References:

No existing reports found with this module or alias. See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: go.thethings.network/lorawan-stack
    - module: go.thethings.network/lorawan-stack/v3
      versions:
        - fixed: 3.24.1
      vulnerable_at: 3.24.0
summary: lorawan-stack Open Redirect vulnerability in go.thethings.network/lorawan-stack
cves:
    - CVE-2023-26494
ghsas:
    - GHSA-5fwq-9x7j-2qpg
references:
    - advisory: https://github.com/advisories/GHSA-5fwq-9x7j-2qpg
    - advisory: https://nvd.nist.gov/vuln/detail/CVE-2023-26494
    - fix: https://github.com/TheThingsNetwork/lorawan-stack/commit/f06776028bdb3994847fc6067613dc61a2b3559e
    - web: https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98b0457ae64de5bfc/pkg/webui/account/views/login/index.js#L90-L90
    - web: https://github.com/TheThingsNetwork/lorawan-stack/blob/ecdef730f176c02f7c9afce98b0457ae64de5bfc/pkg/webui/account/views/token-login/index.js#L74-L74
    - web: https://github.com/TheThingsNetwork/lorawan-stack/releases/tag/v3.24.1
    - web: https://securitylab.github.com/advisories
    - web: https://securitylab.github.com/advisories/GHSL-2022-138_lorawan-stack
notes:
    - fix: 'go.thethings.network/lorawan-stack: could not add vulnerable_at: no fix, but could not find latest version from proxy: HTTP GET /go.thethings.network/lorawan-stack/@latest returned status 404 Not Found'
source:
    id: GHSA-5fwq-9x7j-2qpg
    created: 2024-08-05T22:03:55.438004227Z
review_status: UNREVIEWED
gopherbot commented 3 months ago

Change https://go.dev/cl/603715 mentions this issue: data/reports: add 20 unreviewed reports

gopherbot commented 3 months ago

Change https://go.dev/cl/603716 mentions this issue: data/reports: add 19 unreviewed reports