GHSA-g96c-x7rh-99r3

Suggest an improvement
Source
https://github.com/advisories/GHSA-g96c-x7rh-99r3
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/07/GHSA-g96c-x7rh-99r3/GHSA-g96c-x7rh-99r3.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-g96c-x7rh-99r3
Aliases
Published
2023-07-06T20:51:48Z
Modified
2024-02-16T08:05:54.421677Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N CVSS Calculator
Summary
Graylog vulnerable to insecure source port usage for DNS queries
Details

Summary

Graylog utilises only one single source port for DNS queries.

Details

Graylog seems to bind a single socket for outgoing DNS queries. That socket is bound to a random port number which is not changed again. This goes against recommended practice since 2008, when Dan Kaminsky discovered how easy is to carry out DNS cache poisoning attacks. In order to prevent cache poisoning with spoofed DNS responses, it is necessary to maximise the uncertainty in the choice of a source port for a DNS query.

PoC

The attached figure shows the source ports distribution difference between Graylog configured to use a data adapter based on DNS queries and ISC Bind. The source port distribution of the DNS queries sent from Graylog to a recursive DNS name server running Bind (CLIENTQUERY) are depicted in purple, while the queries sent from the recursive DNS server to the authoritatives (RESOLVERQUERY) are plotted in green color. As it can be observed, in contrast to ISC Bind which presents a heterogeneous usage of source port, Graylog utilises a single source port.

image

Impact

Although unlikely in many setups, an external attacker could inject forged DNS responses into a Graylog's lookup table cache. In order to prevent this, it is at least recommendable to distribute the DNS queries through a pool of distinct sockets, each of them with a random source port and renew them periodically.

(Credit to Iratxe Niño from Fundación Sarenet and Borja Marcos from Sarenet)

Database specific
{
    "nvd_published_at": "2023-08-31T18:15:09Z",
    "cwe_ids": [
        "CWE-345"
    ],
    "severity": "LOW",
    "github_reviewed": true,
    "github_reviewed_at": "2023-07-06T20:51:48Z"
}
References

Affected packages

Maven / org.graylog2:graylog2-server

Package

Name
org.graylog2:graylog2-server
View open source insights on deps.dev
Purl
pkg:maven/org.graylog2/graylog2-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
5.1.0
Fixed
5.1.3

Affected versions

5.*

5.1.0
5.1.1
5.1.2

Maven / org.graylog2:graylog2-server

Package

Name
org.graylog2:graylog2-server
View open source insights on deps.dev
Purl
pkg:maven/org.graylog2/graylog2-server

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.9

Affected versions

0.*

0.20.0-rc.1-1
0.21.0-beta2
0.21.0-beta3
0.21.0-beta4
0.21.0-rc.1
0.90.0
0.90.1
0.90.3
0.91.0-rc.1
0.91.1
0.91.3
0.92.0-beta.1
0.92.0-rc.1
0.92.0
0.92.1-rc.1
0.92.1
0.92.2
0.92.3
0.92.4

1.*

1.0.0-beta.1
1.0.0-beta.2
1.0.0-beta.3
1.0.0-rc.1
1.0.0-rc.2
1.0.0-rc.3
1.0.0-rc.4
1.0.0
1.0.1
1.0.2
1.1.0-beta.1
1.1.0-beta.2
1.1.0-beta.3
1.1.0-rc.1
1.1.0-rc.2
1.1.0-rc.3
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.2.0-rc.1
1.2.0-rc.2
1.2.0-rc.3
1.2.0-rc.4
1.2.0
1.2.1
1.2.2
1.3.0-beta.1
1.3.0-beta.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4

2.*

2.0.0-alpha.1
2.0.0-alpha.2
2.0.0-alpha.3
2.0.0-alpha.4
2.0.0-alpha.5
2.0.0-beta.1
2.0.0-beta.2
2.0.0-beta.3
2.0.0-rc.1
2.0.0
2.0.1
2.0.2
2.0.3
2.1.0-alpha.1
2.1.0-alpha.2
2.1.0-beta.1
2.1.0-beta.2
2.1.0-beta.3
2.1.0-beta.4
2.1.0-rc.1
2.1.0
2.1.1
2.1.2
2.1.3
2.2.0-alpha.1
2.2.0-alpha.2
2.2.0-alpha.3
2.2.0-alpha.4
2.2.0-beta.1
2.2.0-beta.2
2.2.0-beta.3
2.2.0-beta.4
2.2.0-beta.5
2.2.0-beta.6
2.2.0-rc.1
2.2.0
2.2.1
2.2.2
2.2.3
2.3.0-alpha.1
2.3.0-alpha.2
2.3.0-alpha.3
2.3.0-beta.1
2.3.0-rc.1
2.3.0-rc.2
2.3.0
2.3.1
2.3.2
2.4.0-alpha.1
2.4.0-alpha.2
2.4.0-alpha.3
2.4.0-beta.1
2.4.0-beta.2
2.4.0-beta.3
2.4.0-beta.4
2.4.0-rc.1
2.4.0-rc.2
2.4.0
2.4.1
2.4.2
2.4.3
2.4.4
2.4.5
2.4.6
2.4.7
2.5.0-alpha.1
2.5.0-beta.1
2.5.0
2.5.1
2.5.2

3.*

3.0.0-alpha.0
3.0.0-alpha.1
3.0.0-alpha.2
3.0.0-alpha.3
3.0.0-alpha.4
3.0.0-alpha.5
3.0.0-beta.1
3.0.0-beta.2
3.0.0-beta.3
3.0.0-beta.4
3.0.0-rc.1
3.0.0-rc.2
3.0.0
3.0.1
3.0.2
3.1.0-beta.2
3.1.0-beta.3
3.1.0-rc.1
3.1.0-rc.2
3.1.0
3.1.1
3.1.2
3.1.3
3.1.4
3.2.0
3.2.1
3.2.2
3.2.3
3.2.4
3.2.5
3.3.0-beta.3
3.3.0-rc.1
3.3.0
3.3.2
3.3.3
3.3.4
3.3.5
3.3.6
3.3.7
3.3.8
3.3.9
3.3.10
3.3.11
3.3.12
3.3.13
3.3.14
3.3.15
3.3.17

4.*

4.0.0-beta.4
4.0.0-rc.1
4.0.0-rc.2
4.0.0
4.0.1
4.0.2
4.0.3
4.0.4
4.0.5
4.0.6
4.0.7
4.0.8
4.0.9
4.0.10
4.0.11
4.0.12
4.0.13
4.0.14
4.0.16
4.0.17
4.1.0-beta.1
4.1.0-beta.2
4.1.0-rc.1
4.1.0
4.1.1
4.1.2
4.1.3
4.1.4
4.1.5
4.1.6
4.1.7
4.1.8
4.1.9
4.1.11
4.1.12
4.1.13
4.1.14
4.2.0-beta.1
4.2.0-rc.1
4.2.0
4.2.1
4.2.2
4.2.3
4.2.5
4.2.6
4.2.7
4.2.8
4.2.9
4.2.10
4.2.11
4.2.12
4.2.13
4.3.0
4.3.1
4.3.2
4.3.3
4.3.4
4.3.5
4.3.6
4.3.7
4.3.8
4.3.9
4.3.10
4.3.11
4.3.12
4.3.13
4.3.14
4.3.15

5.*

5.0.0
5.0.1
5.0.2
5.0.3
5.0.4
5.0.5
5.0.6
5.0.7
5.0.8