Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0yODk0LXFjcWYtZzIzZ84AA2Ml
asyncua Improper Authentication vulnerability
Versions of the package asyncua before 0.9.96 are vulnerable to Improper Authentication such that it is possible to access Address Space without encryption and authentication.
Note:
This issue is a result of missing checks for services that require an active session.
Permalink: https://github.com/advisories/GHSA-2894-qcqf-g23gJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0yODk0LXFjcWYtZzIzZ84AA2Ml
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: 7 months ago
Updated: 6 months ago
CVSS Score: 7.5
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-2894-qcqf-g23g, CVE-2023-26150
References:
- https://nvd.nist.gov/vuln/detail/CVE-2023-26150
- https://github.com/FreeOpcUa/opcua-asyncio/issues/1014
- https://github.com/FreeOpcUa/opcua-asyncio/pull/1015
- https://github.com/FreeOpcUa/opcua-asyncio/commit/2be7ce80df05de8d6c6ae1ebce6fa2bb7147844a
- https://github.com/FreeOpcUa/opcua-asyncio/commit/b4106dfd5037423c9d1810b48a97296b59cde513
- https://gist.github.com/artfire52/84f7279a4119d6f90381ac49d7121121
- https://github.com/FreeOpcUa/opcua-asyncio/releases/tag/v0.9.96
- https://security.snyk.io/vuln/SNYK-PYTHON-ASYNCUA-5673435
- https://github.com/pypa/advisory-database/tree/main/vulns/asyncua/PYSEC-2023-189.yaml
- https://github.com/advisories/GHSA-2894-qcqf-g23g
Blast Radius: 12.5
Affected Packages
pypi:asyncua
Dependent packages: 8Dependent repositories: 46
Downloads: 131,474 last month
Affected Version Ranges: < 0.9.96
Fixed in: 0.9.96
All affected versions: 0.5.0, 0.5.1, 0.6.0, 0.6.1, 0.8.0, 0.8.1, 0.8.2, 0.8.3, 0.8.4, 0.9.0, 0.9.1, 0.9.2, 0.9.3, 0.9.6, 0.9.8, 0.9.9, 0.9.10, 0.9.11, 0.9.12, 0.9.14, 0.9.90, 0.9.91, 0.9.92, 0.9.93, 0.9.94, 0.9.95
All unaffected versions: 0.9.96, 0.9.97, 0.9.98, 1.0.0, 1.0.1, 1.0.2, 1.0.3, 1.0.4, 1.0.5, 1.0.6, 1.1.0