Timing Attack Vulnerability in Apache Mesos Executor HTTP API
CVE-2018-8023
5.9MEDIUM
What is CVE-2018-8023?
Apache Mesos has a vulnerability within its JWT authentication implementation for the Executor HTTP API. Versions prior to 1.4.2 and specific builds of 1.5.x and 1.6.0 utilize a non-secure string comparison method, allowing an attacker to exploit timing discrepancies during JWT validation. This timing attack can facilitate unauthorized access, enabling malicious users to deduce the correct HMAC value by measuring the response time variations in the API's validation process.
Affected Version(s)
Apache Mesos versions prior to 1.4.2
Apache Mesos 1.5.0, 1.5.1
Apache Mesos 1.6.0