Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1obTM3LTl4aDItcTQ5Oc4AAtHw
Possible leak of key's raw field if declared length is incorrect
Impact
If a field of a key is shorter than it is declared to be, the parser raises an error with a message containing the raw field value. An attacker able to modify the declared length of a key's sensitive field can thus expose the raw value of that field.
Patches
Upgrade to version 0.0.6, which no longer includes the raw field value in the error message.
Workarounds
N/A
References
N/A
For more information
If you have any questions or comments about this advisory:
- Open an issue in openssh_key_parser
JSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1obTM3LTl4aDItcTQ5Oc4AAtHw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: High
Classification: General
Published: almost 2 years ago
Updated: over 1 year ago
CVSS Score: 7.7
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Identifiers: GHSA-hm37-9xh2-q499, CVE-2022-31124
References:
- https://github.com/scottcwang/openssh_key_parser/security/advisories/GHSA-hm37-9xh2-q499
- https://github.com/scottcwang/openssh_key_parser/pull/5
- https://github.com/scottcwang/openssh_key_parser/commit/26e0a471e9fdb23e635bc3014cf4cbd2323a08d3
- https://github.com/scottcwang/openssh_key_parser/commit/274447f91b4037b7050ae634879b657554523b39
- https://github.com/scottcwang/openssh_key_parser/commit/d5b53b4b7e76c5b666fc657019dbf864fb04076c
- https://nvd.nist.gov/vuln/detail/CVE-2022-31124
- https://github.com/pypa/advisory-database/tree/main/vulns/openssh-key-parser/PYSEC-2022-233.yaml
- https://github.com/advisories/GHSA-hm37-9xh2-q499
Blast Radius: 0.0
Affected Packages
pypi:openssh-key-parser
Dependent packages: 0Dependent repositories: 1
Downloads: 281 last month
Affected Version Ranges: < 0.0.6
Fixed in: 0.0.6
All affected versions: 0.0.1, 0.0.2, 0.0.3, 0.0.4, 0.0.5
All unaffected versions: 0.0.6, 0.0.7