iBet uBet web content aggregator. Adding the entire web to your favor.
iBet uBet web content aggregator. Adding the entire web to your favor.



Link to original content: http://phabricator.wikimedia.org/tag/vuln-vulncomponent/
Vuln-VulnComponent
Page MenuHomePhabricator

Vuln-VulnComponentTag
ActivePublic

Members

  • This project does not have any members.
  • View All

Watchers

  • This project does not have any watchers.
  • View All

Details

Description

This tag is used to group security bugs by their general classification. If a vulnerable component is exploited, such bugs allow a range of attacks. See OWASP Top 10 2017 - A9

Parent project: Security-Team

Recent Activity

Thu, Nov 7

Nikerabbit removed projects from T309772: npm audit reports several security issues with Service runner: LPL Essential (LPL Essential 2024 Jul-Oct), CX-cxserver.

Removing CXserver and sprint tags as it no longer applies to us.

Thu, Nov 7, 8:31 AM · Vuln-VulnComponent, MediaWiki-Engineering, Security, service-runner

Thu, Oct 31

santhosh added a comment to T309772: npm audit reports several security issues with Service runner.

CXServer removed the dependency on service-runner T357950: Remove servicerunner dependency for cxserver and deployed to production last week. Since service-runner and the associated service template had huge influence on how a nodejs servie is written, it was not an easy migration. This was also partly due to the fact that cxserver was written in 2015 and then grew to a complex system.

Thu, Oct 31, 5:17 AM · Vuln-VulnComponent, MediaWiki-Engineering, Security, service-runner

Sep 12 2024

sbassett set Author Affiliation to tech on T374588: GitLab Critical Patch Release: 17.3.2, 17.2.5, 17.1.7 .
Sep 12 2024, 5:04 PM · SecTeam-Processed, Vuln-VulnComponent, collaboration-services, GitLab (Infrastructure), Security
sbassett edited projects for T374588: GitLab Critical Patch Release: 17.3.2, 17.2.5, 17.1.7 , added: Vuln-VulnComponent, SecTeam-Processed; removed Security-Team.
Sep 12 2024, 5:04 PM · SecTeam-Processed, Vuln-VulnComponent, collaboration-services, GitLab (Infrastructure), Security

Sep 5 2024

Yaron_Koren closed T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226 as Resolved.

I think this can be closed.

Sep 5 2024, 1:06 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team

Aug 22 2024

sbassett raised the priority of T373124: update ingress-nginx for CVE-2024-7646 from Medium to High.
Aug 22 2024, 9:51 PM · Vuln-VulnComponent, SecTeam-Processed, Security, PAWS
sbassett triaged T373124: update ingress-nginx for CVE-2024-7646 as Medium priority.
Aug 22 2024, 9:51 PM · Vuln-VulnComponent, SecTeam-Processed, Security, PAWS
sbassett edited projects for T373124: update ingress-nginx for CVE-2024-7646, added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Aug 22 2024, 9:49 PM · Vuln-VulnComponent, SecTeam-Processed, Security, PAWS

Aug 20 2024

brennen closed T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F as Resolved.
Aug 20 2024, 4:50 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Aug 19 2024

Aklapper added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

See the previous three comments

Aug 19 2024, 7:59 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Mstyles added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

@Aklapper are you okay to resolve this ticket?

Aug 19 2024, 4:12 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Aug 15 2024

sbassett moved T371569: SMTP smuggling vulnerability report from Watching to Our Part Is Done on the Security-Team board.
Aug 15 2024, 2:30 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett changed the visibility for T371569: SMTP smuggling vulnerability report.
Aug 15 2024, 2:30 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Aug 13 2024

brennen added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

If this has bitten us anywhere else, I'm not aware of it. I think it seems fine to resolve at this stage.

Aug 13 2024, 10:45 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Dzahn added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

modules/profile/templates/idp/client/httpd-puppetboard-ng.erb is for https://puppetboard.wikimedia.org

Aug 13 2024, 8:58 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Aklapper moved T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F from To Triage to Infrastructure on the Phabricator board.
Aug 13 2024, 8:37 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Aklapper added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

I'm tempted to resolve this task tagged with Phabricator and create a separate one for MediaWiki-Vagrant (is the modules/profile/templates/idp/client/httpd-puppetboard-ng.erb result in Puppet relevant?) because I dislike fixed issues displayed as unresolved tasks in my backlog. Eh?

Aug 13 2024, 8:36 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Aug 12 2024

jhathaway closed T371569: SMTP smuggling vulnerability report as Resolved.
Aug 12 2024, 6:55 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
jhathaway added a comment to T371569: SMTP smuggling vulnerability report.

@jhathaway -

Would that be the extent of our exposure to this issue, in your estimation? e.g. is the above good enough to resolve this task? We'd need to defer to you and SRE on that assessment.

Aug 12 2024, 6:54 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Aug 8 2024

sbassett set Author Affiliation to tech on T372026: GitLab Security Release: 17.2.2, 17.1.4, 17.0.6.
Aug 8 2024, 4:19 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Security
sbassett edited projects for T372026: GitLab Security Release: 17.2.2, 17.1.4, 17.0.6, added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Aug 8 2024, 4:18 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Security

Aug 7 2024

sbassett set Author Affiliation to tech on T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Aug 7 2024, 6:52 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
sbassett set Author Affiliation to tech on T371953: GitLab Security Release: GitLab Patch Release: 17.2.1, 17.1.3, 17.0.5 .
Aug 7 2024, 6:52 PM · Vuln-VulnComponent, SecTeam-Processed, GitLab (Infrastructure), collaboration-services, Security
sbassett edited projects for T371953: GitLab Security Release: GitLab Patch Release: 17.2.1, 17.1.3, 17.0.5 , added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Aug 7 2024, 6:51 PM · Vuln-VulnComponent, SecTeam-Processed, GitLab (Infrastructure), collaboration-services, Security
JJMC89 merged T371953: GitLab Security Release: GitLab Patch Release: 17.2.1, 17.1.3, 17.0.5 into T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Aug 7 2024, 7:55 AM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security

Aug 5 2024

sbassett moved T371569: SMTP smuggling vulnerability report from Incoming to Watching on the Security-Team board.
Aug 5 2024, 4:13 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Aug 2 2024

sbassett added a comment to T371569: SMTP smuggling vulnerability report.

Our postfix servers have now been configured with the "long term fix", T370011, https://www.postfix.org/smtp-smuggling.html#back-ports

Our lists server has Exim4 4.96-15+deb12u4, which has a patch included to fix the attack vector according to https://security-tracker.debian.org/tracker/CVE-2023-51766

Aug 2 2024, 3:56 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Aug 1 2024

jhathaway added a comment to T371569: SMTP smuggling vulnerability report.

Our postfix servers have now been configured with the "long term fix", T370011, https://www.postfix.org/smtp-smuggling.html#back-ports

Aug 1 2024, 8:39 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Jul 31 2024

sbassett added projects to T371569: SMTP smuggling vulnerability report: Infrastructure-Foundations, Vuln-VulnComponent.
Jul 31 2024, 10:44 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team
sbassett updated subscribers of T371569: SMTP smuggling vulnerability report.
Jul 31 2024, 10:44 PM · SecTeam-Processed, Vuln-VulnComponent, Infrastructure-Foundations, Security, Security-Team

Jul 26 2024

brennen added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

Doesn't look like a lot else in codesearch, at least - a couple in MediaWiki-Vagrant:

Jul 26 2024, 7:11 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
sbassett added a project to T309772: npm audit reports several security issues with Service runner: Vuln-VulnComponent.
Jul 26 2024, 1:47 PM · Vuln-VulnComponent, MediaWiki-Engineering, Security, service-runner
Jelto closed T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5 as Resolved.

All instances updated, thanks again @eoghan and @Dzahn for preparing the update on the other instances!

Jul 26 2024, 11:09 AM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
Jelto updated the task description for T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Jul 26 2024, 11:08 AM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
Jelto claimed T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Jul 26 2024, 8:07 AM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security

Jul 25 2024

eoghan updated the task description for T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Jul 25 2024, 10:13 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
eoghan updated the task description for T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5.
Jul 25 2024, 10:01 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security
sbassett edited projects for T370973: GitLab Security Release 17.2.1, 17.1.3, 17.0.5, added: SecTeam-Processed, Vuln-VulnComponent; removed Security-Team.
Jul 25 2024, 4:10 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, GitLab, Security

Jul 24 2024

hashar added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.
  • The phorge module in Puppet should be adjusted

Done

Jul 24 2024, 5:02 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Jul 23 2024

Maintenance_bot removed a project from T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F: Patch-For-Review.
Jul 23 2024, 6:32 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Dzahn added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.
  • The phorge module in Puppet should be adjusted
Jul 23 2024, 5:50 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
gerritbot added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

Change #1056207 merged by Dzahn:

[operations/puppet@production] phorge: add UnsafeAllow3F rewrite flag

https://gerrit.wikimedia.org/r/1056207

Jul 23 2024, 5:49 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
gerritbot added a project to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F: Patch-For-Review.
Jul 23 2024, 5:23 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
gerritbot added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

Change #1056207 had a related patch set uploaded (by Dzahn; author: Dzahn):

[operations/puppet@production] phorge: add UnsafeAllow3F rewrite flag

https://gerrit.wikimedia.org/r/1056207

Jul 23 2024, 5:22 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
hashar added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

Is the B flag the reason the issue triggers? From what I understand it encodes the requested URI before it is processed and surely any legit ones having a question mark will end up triggering it. Maybe the upstream code should have exempted those cases, then I don't understand the attack vector :-/ What I am wondering is what is the sufficient condition to trigger the error so that we can audit all of our RewriteRule.

Jul 23 2024, 8:28 AM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security

Jul 22 2024

Aklapper added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

Upstreamed as https://we.phorge.it/T15889

Jul 22 2024, 9:11 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
Mstyles changed the visibility for T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226.
Jul 22 2024, 4:56 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team
Mstyles moved T370022: Version `4.3.5` of `smarty/smarty` library in Extension:Widgets library has CVE-2024-35226 from In Progress to Our Part Is Done on the Security-Team board.
Jul 22 2024, 4:56 PM · SecTeam-Processed, Vuln-VulnComponent, Patch-For-Review, MediaWiki-extensions-Widgets, Security, Security-Team
Mstyles added a comment to T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F.

@Aklapper since the gerrit patch is public this ticket is okay to be public as well. I went ahead and changed the policy

Jul 22 2024, 4:35 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security
sbassett edited projects for T370110: Apache 2.4.61 throws a 403 Forbidden for links containing %3F, added: Vuln-VulnComponent; removed Vuln-Misconfiguration.
Jul 22 2024, 4:32 PM · Vuln-VulnComponent, SecTeam-Processed, collaboration-services, Release-Engineering-Team (Priority Backlog 📥), Wikimedia-Apache-configuration, Phabricator, User-brennen, Security