Timing Attack Vulnerability in Apache Mesos Executor HTTP API
CVE-2018-8023
5.9MEDIUM
Summary
Apache Mesos has a vulnerability within its JWT authentication implementation for the Executor HTTP API. Versions prior to 1.4.2 and specific builds of 1.5.x and 1.6.0 utilize a non-secure string comparison method, allowing an attacker to exploit timing discrepancies during JWT validation. This timing attack can facilitate unauthorized access, enabling malicious users to deduce the correct HMAC value by measuring the response time variations in the API's validation process.
Affected Version(s)
Apache Mesos versions prior to 1.4.2
Apache Mesos 1.5.0, 1.5.1
Apache Mesos 1.6.0
References
CVSS V3.1
Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved