Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Critical vulnerabilities discovered in Lemur #3463

Closed
csine-pro opened this issue Mar 10, 2021 · 0 comments
Closed

Critical vulnerabilities discovered in Lemur #3463

csine-pro opened this issue Mar 10, 2021 · 0 comments
Assignees
Labels
security Pull requests that address a security vulnerability

Comments

@csine-pro
Copy link
Contributor

Dear Lemur community,

During a commissioned pentest of Lemur version 0.8.0 (a Netflix OSS project, available here), three vulnerabilities were identified in Lemur’s codebase. At a high level, the vulnerabilities enable an authenticated user to retrieve/access unauthorized information, including private keys.

Presently, we have no reason to believe that these vulnerabilities have been exploited. Evidence of access to sensitive information would be visible in HTTP request logs.

We have already prepared the patches to fix these vulnerabilities, and will be raising PRs to Lemur’s GitHub repository one week from today. On the same day, we will release a new version of Lemur (0.9.0) which will contain the patches. We recommend that all Lemur users upgrade immediately after version 0.9.0 has been released. We may disclose additional details regarding the vulnerabilities following the updated release of Lemur.

Thanks,
Lemur Team

@hosssha hosssha added the security Pull requests that address a security vulnerability label Mar 10, 2021
@hosssha hosssha pinned this issue Mar 10, 2021
@hosssha hosssha closed this as completed Mar 22, 2021
@hosssha hosssha unpinned this issue Mar 22, 2021
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
security Pull requests that address a security vulnerability
Projects
None yet
Development

No branches or pull requests

4 participants