GHSA-fh7v-q458-7vmw

Suggest an improvement
Source
https://github.com/advisories/GHSA-fh7v-q458-7vmw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-fh7v-q458-7vmw/GHSA-fh7v-q458-7vmw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-fh7v-q458-7vmw
Published
2024-12-02T18:39:39Z
Modified
2024-12-02T18:46:09Z
Summary
ibexa/http-cache affected by Breach with Varnish VCL
Details

Impact

This is not a vulnerability in the code per se, but included Varnish VCL templates enable compression of API and JSON messages. This is a potential case of the BREACH vulnerability, which affects HTTP compression, where secrets can be extracted through carefully crafted requests. The fix disables compression in these templates. Please make sure to make the same change in your configuration files, see the release notes for specific instructions. Please check your web server configuration as well.

Patches

Workarounds

Make sure HTTP compression is disabled for REST API requests and other communication that might contain secrets.

References

Database specific
{
    "cwe_ids":  [],
    "github_reviewed":  true,
    "github_reviewed_at":  "2024-12-02T18:39:39Z",
    "nvd_published_at":  null,
    "severity":  "MODERATE"
}
References

Affected packages

Packagist / ibexa/http-cache

Package

Name
ibexa/http-cache
Purl
pkg:composer/ibexa/http-cache

Affected ranges

Type
ECOSYSTEM
Events
Introduced
4.6.0
Fixed
4.6.14

Affected versions

v4.*
v4.6.0
v4.6.1
v4.6.2
v4.6.3
v4.6.4
v4.6.5
v4.6.6
v4.6.7
v4.6.8
v4.6.9
v4.6.10
v4.6.11
v4.6.12
v4.6.13

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/12/GHSA-fh7v-q458-7vmw/GHSA-fh7v-q458-7vmw.json"