{"id":"GHSA-rjmq-6v55-4rjv","summary":"Improper Authorization in org.cometd.oort","details":"### Impact\nInternal usage of Oort and Seti channels is improperly authorized, so any remote user could subscribe and publish to those channels.\nBy subscribing to those channels, a remote user may be able to watch cluster-internal traffic that contains other user's (possibly sensitive) data.\nBy publishing to those channels, a remote user may be able to create/modify/delete other user's data and modify the cluster structure.\nThe issue impacts any version up to 5.0.10, 6.0.5 and 7.0.5.\n\n### Patches\nThe issue has been fixed in 5.0.11, 6.0.6 and 7.0.6.\n\n### Workarounds\nThe workaround is to install a custom `SecurityPolicy` that forbids subscription and publishing to remote, non-Oort, sessions on Oort and Seti channels.\nThis workaround could be implemented in any affected version.\n\n### References\ncometd/cometd#1146\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [security@webtide.com](mailto:security@webtide.com)\n\n### Credits\nhttps://www.redteam-pentesting.de/","aliases":["CVE-2022-24721"],"modified":"2023-11-01T04:58:06.075618Z","published":"2022-03-15T19:02:36Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-03-15T19:02:36Z","nvd_published_at":"2022-03-15T14:15:00Z","cwe_ids":["CWE-863"]},"references":[{"type":"WEB","url":"https://github.com/cometd/cometd/security/advisories/GHSA-rjmq-6v55-4rjv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-24721"},{"type":"WEB","url":"https://github.com/cometd/cometd/issues/1146"},{"type":"WEB","url":"https://github.com/cometd/cometd/commit/bb445a143fbf320f17c62e340455cd74acfb5929"},{"type":"PACKAGE","url":"https://github.com/cometd/cometd"}],"affected":[{"package":{"name":"org.cometd.java:cometd-java-oort","ecosystem":"Maven","purl":"pkg:maven/org.cometd.java/cometd-java-oort"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.11"}]}],"versions":["1.0.0","1.0.0rc0","1.0.1","1.0.beta10","1.0.beta8","1.0.beta9","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","2.0.0","2.0.0.RC1","2.0.0.RC2","2.0.0.RC3","2.0.beta0","2.0.beta1","2.1.0","2.1.0.RC","2.1.0.beta1","2.1.0.beta2","2.1.1","2.2.0","2.2.0.RC0","2.3.0","2.3.0.RC1","2.3.1","2.4.0","2.4.0.RC1","2.4.0.RC2","2.4.0.RC3","2.4.0.beta1","2.4.0.beta2","2.4.1","2.4.2","2.4.3","2.5.0","2.5.0-RC1","2.5.0-beta1","2.5.0-beta2","2.5.0-beta3","2.5.1","2.6.0","2.6.0-RC1","2.7.0","2.7.0-RC1","2.7.0-beta1","2.7.0-beta2","2.8.0","2.8.0-RC1","2.8.0-beta1","2.9.0","2.9.0-beta1","2.9.1","3.0.0","3.0.0.RC1","3.0.0.beta1","3.0.0.beta2","3.0.1","3.0.10","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.0-BETA0","3.1.0-BETA1","3.1.0-BETA2","3.1.0-RC0","3.1.0-RC1","3.1.1","3.1.10","3.1.11","3.1.12","3.1.13","3.1.14","3.1.2","3.1.2-BETA0","3.1.2-BETA1","3.1.2-RC0","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.1.9","4.0.0","4.0.0-BETA0","4.0.0-BETA1","4.0.1","4.0.2","4.0.3","4.0.4","4.0.5","4.0.6","4.0.7","4.0.8","4.0.9","5.0.0","5.0.0-BETA0","5.0.0-BETA1","5.0.1","5.0.10","5.0.2","5.0.3","5.0.4","5.0.5","5.0.6","5.0.7","5.0.8","5.0.9"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-rjmq-6v55-4rjv/GHSA-rjmq-6v55-4rjv.json"}},{"package":{"name":"org.cometd.java:cometd-java-oort","ecosystem":"Maven","purl":"pkg:maven/org.cometd.java/cometd-java-oort"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"6.0.0"},{"fixed":"6.0.6"}]}],"versions":["6.0.0","6.0.1","6.0.2","6.0.3","6.0.4","6.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-rjmq-6v55-4rjv/GHSA-rjmq-6v55-4rjv.json"}},{"package":{"name":"org.cometd.java:cometd-java-oort","ecosystem":"Maven","purl":"pkg:maven/org.cometd.java/cometd-java-oort"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"7.0.0"},{"fixed":"7.0.6"}]}],"versions":["7.0.0","7.0.1","7.0.2","7.0.3","7.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/03/GHSA-rjmq-6v55-4rjv/GHSA-rjmq-6v55-4rjv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}