Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS0zcncyLXdmYzgtd21qNc4AA0xu
Fides Webserver Vulnerable to SVG Bomb File Uploads
Impact
The Fides webserver is vulnerable to a type of Denial of Service (DoS) attack. Attackers can exploit this vulnerability to upload zip files containing malicious SVG bombs (similar to a billion laughs attack), causing resource exhaustion in Admin UI browser tabs and creating a persistent denial of service of the 'new connector' page (datastore-connection/new
).
This vulnerability affects Fides versions 2.11.0
through 2.15.1
. Exploitation is limited to users with elevated privileges with the CONNECTOR_TEMPLATE_REGISTER
scope, which includes root users and users with the owner role.
Patches
The vulnerability has been patched in Fides version 2.16.0
. Users are advised to upgrade to this version or later to secure their systems against this threat.
Workarounds
There is no known workaround to remediate this vulnerability without upgrading.
Permalink: https://github.com/advisories/GHSA-3rw2-wfc8-wmj5JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS0zcncyLXdmYzgtd21qNc4AA0xu
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Low
Classification: General
Published: over 1 year ago
Updated: about 1 year ago
CVSS Score: 2.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
Identifiers: GHSA-3rw2-wfc8-wmj5, CVE-2023-37481
References:
- https://github.com/ethyca/fides/security/advisories/GHSA-3rw2-wfc8-wmj5
- https://github.com/ethyca/fides/commit/8beaace082b325e693dc7682029a3cb7e6c2b69d
- https://github.com/ethyca/fides/releases/tag/2.16.0
- https://nvd.nist.gov/vuln/detail/CVE-2023-37481
- https://github.com/advisories/GHSA-3rw2-wfc8-wmj5
Blast Radius: 1.0
Affected Packages
pypi:ethyca-fides
Dependent packages: 0Dependent repositories: 0
Downloads: 29,180 last month
Affected Version Ranges: >= 2.11.0, < 2.16.0
Fixed in: 2.16.0
All affected versions: 2.11.0, 2.12.0, 2.12.1, 2.13.0, 2.14.0, 2.14.1, 2.14.2, 2.15.0, 2.15.1
All unaffected versions: 1.9.9, 2.0.0, 2.1.0, 2.2.0, 2.2.1, 2.2.2, 2.3.0, 2.3.1, 2.4.0, 2.5.0, 2.5.1, 2.6.0, 2.6.1, 2.6.2, 2.6.3, 2.6.4, 2.6.5, 2.6.6, 2.7.0, 2.7.1, 2.8.0, 2.8.1, 2.8.2, 2.8.3, 2.9.0, 2.9.1, 2.9.2, 2.10.0, 2.16.0, 2.17.0, 2.17.1, 2.18.0, 2.19.0, 2.19.1, 2.20.0, 2.20.1, 2.20.2, 2.21.0, 2.22.0, 2.22.1, 2.23.0, 2.23.1, 2.23.2, 2.23.3, 2.24.0, 2.24.1, 2.25.0, 2.26.0, 2.26.3, 2.27.0, 2.28.0, 2.29.0, 2.30.0, 2.30.1, 2.31.0, 2.32.0, 2.33.0, 2.33.1, 2.34.0, 2.35.0, 2.35.1, 2.36.0, 2.37.0, 2.38.0, 2.38.1, 2.39.0, 2.39.1, 2.39.2, 2.40.0, 2.41.0, 2.42.0, 2.42.1, 2.43.0, 2.43.2, 2.44.0, 2.45.0, 2.45.1, 2.45.2, 2.46.0, 2.46.1, 2.46.2, 2.47.0, 2.47.1, 2.48.0, 2.48.1, 2.48.2, 2.49.0