Products
Hydra
Source
security-advisories@github.com
Tags
CVE-2024-45049 details
Published : Aug. 27, 2024, 9:15 p.m.
Last Modified : Aug. 27, 2024, 9:15 p.m.
Last Modified : Aug. 27, 2024, 9:15 p.m.
Description
Hydra is a Continuous Integration service for Nix based projects. It is possible to trigger evaluations in Hydra without any authentication. Depending on the size of evaluations, this can impact the availability of systems. The problem can be fixed by applying https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 to any Hydra package. Users are advised to upgrade. Users unable to upgrade should deny the `/api/push` route in a reverse proxy. This also breaks the "Evaluate jobset" button in the frontend.
CVSS Score
1 | 2 | 3 | 4 | 5 | 6 | 7.5 | 8 | 9 | 10 |
---|
Weakness
Weakness | Name | Description |
---|---|---|
CWE-306 | Missing Authentication for Critical Function | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |
CVSS Data
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Base Score
7.5
Exploitability Score
3.9
Impact Score
3.6
Base Severity
HIGH
Vector String : CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
References
URL | Source |
---|---|
https://github.com/NixOS/hydra/commit/f73043378907c2c7e44f633ad764c8bdd1c947d5 | security-advisories@github.com |
https://github.com/NixOS/hydra/security/advisories/GHSA-xv29-v93r-2f5v | security-advisories@github.com |
https://github.com/NixOS/nixpkgs/pull/337766 | security-advisories@github.com |
https://mastodon.delroth.net/@delroth/113029832631860419 | security-advisories@github.com |
This website uses the NVD API, but is not approved or certified by it.