Timing Attack Vulnerability in Apache Mesos Executor HTTP API
CVE-2018-8023

5.9MEDIUM

Key Information:

Vendor
Apache
Vendor
CVE Published:
21 September 2018

Summary

Apache Mesos has a vulnerability within its JWT authentication implementation for the Executor HTTP API. Versions prior to 1.4.2 and specific builds of 1.5.x and 1.6.0 utilize a non-secure string comparison method, allowing an attacker to exploit timing discrepancies during JWT validation. This timing attack can facilitate unauthorized access, enabling malicious users to deduce the correct HMAC value by measuring the response time variations in the API's validation process.

Affected Version(s)

Apache Mesos versions prior to 1.4.2

Apache Mesos 1.5.0, 1.5.1

Apache Mesos 1.6.0

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.