{"id":"GHSA-v988-828w-xvf2","summary":"Authentication Bypass Using an Alternate Path or Channel and Authentication Bypass by Primary Weakness in rucio-webui","details":"### Impact\n`rucio-webui` installations of the `1.26` release line potentially leak the contents of cookies to other sessions within a wsgi container. Impact is that Rucio authentication tokens are leaked to other users accessing the `webui` within a close timeframe, thus allowing users to access the `webui` with the leaked authentication token. Privileges are therefore also escalated.\n\nRucio server / daemons are not affected by this issue, it is isolated to the webui.\n\n### Patches\nThis issue is fixed in the `1.26.7` release of the `rucio-webui`.\n\n### Workarounds\nInstallation of the `1.25.7` `webui` release. The `1.25` and previous webui release lines are not affected by this issue.\n\n### References\nhttps://github.com/rucio/rucio/issues/4928","modified":"2025-02-13T05:31:28.532416Z","published":"2021-10-22T16:21:07Z","database_specific":{"cwe_ids":["CWE-288","CWE-305"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-10-21T21:36:22Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/rucio/rucio/security/advisories/GHSA-v988-828w-xvf2"},{"type":"WEB","url":"https://github.com/rucio/rucio/issues/4810"},{"type":"WEB","url":"https://github.com/rucio/rucio/issues/4928"},{"type":"WEB","url":"https://github.com/rucio/rucio/commit/8f832404ae88d6300e17d7e706b40fe58e0df90c"},{"type":"PACKAGE","url":"https://github.com/rucio/rucio"},{"type":"WEB","url":"https://github.com/rucio/rucio/releases/tag/1.26.7"}],"affected":[{"package":{"name":"rucio-webui","ecosystem":"PyPI","purl":"pkg:pypi/rucio-webui"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"1.26.0"},{"fixed":"1.26.7"}]}],"versions":["1.26.0","1.26.1","1.26.1.post1","1.26.2","1.26.4","1.26.5","1.26.6"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/10/GHSA-v988-828w-xvf2/GHSA-v988-828w-xvf2.json"}}],"schema_version":"1.9.0"}