Upstream information

CVE-2019-7628 at MITRE

Description

Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain access to Pagure on behalf of other users. This issue is found in the API token expiration reminder cron job in files/api_key_expire_mail.py; disabling that job is also a viable solution. (E-mailing a substring of the API key was an attempted, but rejected, solution.)

SUSE information

Overall state of this security issue: Does not affect SUSE products

This issue is currently rated as having moderate severity.

CVSS v2 Scores
  National Vulnerability Database
Base Score 4.3
Vector AV:N/AC:M/Au:N/C:P/I:N/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact None
Availability Impact None
CVSS v3 Scores
  National Vulnerability Database
Base Score 5.9
Vector CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector Network
Attack Complexity High
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality Impact High
Integrity Impact None
Availability Impact None
CVSSv3 Version 3
SUSE Bugzilla entry: 1124762 [RESOLVED / FIXED]

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • pagure >= 5.13.2-2.2
  • pagure-ci >= 5.13.2-2.2
  • pagure-ev >= 5.13.2-2.2
  • pagure-loadjson >= 5.13.2-2.2
  • pagure-logcom >= 5.13.2-2.2
  • pagure-milters >= 5.13.2-2.2
  • pagure-mirror >= 5.13.2-2.2
  • pagure-theme-chameleon >= 5.13.2-2.2
  • pagure-theme-default-openSUSE >= 5.13.2-2.2
  • pagure-theme-default-upstream >= 5.13.2-2.2
  • pagure-theme-pagureio >= 5.13.2-2.2
  • pagure-theme-srcfpo >= 5.13.2-2.2
  • pagure-theme-upstream >= 5.13.2-2.2
  • pagure-web-apache-httpd >= 5.13.2-2.2
  • pagure-web-nginx >= 5.13.2-2.2
  • pagure-webhook >= 5.13.2-2.2
Patchnames:
openSUSE Tumbleweed GA pagure-5.13.2-2.2


SUSE Timeline for this CVE

CVE page created: Fri Feb 8 09:13:16 2019
CVE page last modified: Wed Oct 26 21:48:50 2022