{"id":"GHSA-v988-828w-xvf2","aliases":[],"url":"https://o3.security/vulnerability/GHSA-v988-828w-xvf2","summary":"Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui","details":"### Impact\n`rucio-webui` installations of the `1.26` release line potentially leak the contents of cookies to other sessions within a wsgi container. Impact is that Rucio authentication tokens are leaked to other users accessing the `webui` within a close timeframe, thus allowing users to access the `webui` with the leaked authentication token. Privileges are therefore also escalated.\n\nRucio server / daemons are not affected by this issue, it is isolated to the webui.\n\n### Patches\nThis issue is fixed in the `1.26.7` release of the `rucio-webui`.\n\n### Workarounds\nInstallation of the `1.25.7` `webui` release. The `1.25` and previous webui release lines are not affected by this issue.\n\n### References\nhttps://github.com/rucio/rucio/issues/4928","published":"2021-10-22T16:21:07Z","modified":"2025-02-13T05:31:28.532416Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"rucio-webui","fixedVersion":"1.26.7"}],"fix":{"url":"https://github.com/rucio/rucio/commit/8f832404ae88d6300e17d7e706b40fe58e0df90c","label":"rucio/rucio@8f83240"},"references":[{"type":"WEB","url":"https://github.com/rucio/rucio/security/advisories/GHSA-v988-828w-xvf2"},{"type":"WEB","url":"https://github.com/rucio/rucio/issues/4810"},{"type":"WEB","url":"https://github.com/rucio/rucio/issues/4928"},{"type":"WEB","url":"https://github.com/rucio/rucio/commit/8f832404ae88d6300e17d7e706b40fe58e0df90c"},{"type":"PACKAGE","url":"https://github.com/rucio/rucio"},{"type":"WEB","url":"https://github.com/rucio/rucio/releases/tag/1.26.7"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-02-13T05:31:28.532416Z"}}