Apache Arrow Rust Object Store: AWS WebIdentityToken exposure in log files
Description
Exposure of temporary credentials in logs in Apache Arrow Rust Object Store (object_store crate), version 0.10.1 and earlier on all platforms using AWS WebIdentityTokens.
On certain error conditions, the logs may contain the OIDC token passed to AssumeRoleWithWebIdentity https://docs.aws.amazon.com/STS/latest/APIReference/API_AssumeRoleWithWebIdentity.html . This allows someone with access to the logs to impersonate that identity, including performing their own calls to AssumeRoleWithWebIdentity, until the OIDC token expires. Typically OIDC tokens are valid for up to an hour, although this will vary depending on the issuer.
Users are recommended to use a different AWS authentication mechanism, disable logging or upgrade to version 0.10.2, which fixes this issue.
Details:
When using AWS WebIdentityTokens with the object_store crate, in the event of a failure and automatic retry, the underlying reqwest error, including the full URL with the credentials, potentially in the parameters, is written to the logs.
Thanks to Paul Hatcherian for reporting this vulnerability
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
object_storecrates.io | >= 0.5.0, < 0.10.2 | 0.10.2 |
Affected products
10- osv-coords9 versionspkg:apk/chainguard/parseablepkg:apk/chainguard/qdrantpkg:apk/chainguard/qdrant-oci-compatpkg:apk/chainguard/qdrant-oci-entrypointpkg:apk/wolfi/parseablepkg:apk/wolfi/qdrantpkg:apk/wolfi/qdrant-oci-compatpkg:apk/wolfi/qdrant-oci-entrypointpkg:cargo/object_store
< 1.4.0-r0+ 8 more
- (no CPE)range: < 1.4.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: < 1.4.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: < 1.11.0-r0
- (no CPE)range: >= 0.5.0, < 0.10.2
- Range: 0.5.0
Patches
Vulnerability mechanics
References
7- github.com/advisories/GHSA-c2hf-vcmr-qjrfghsaADVISORY
- lists.apache.org/thread/3t0povdppnt2czv6crlsqhvyko93kcrgghsavendor-advisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2024-41178ghsaADVISORY
- www.openwall.com/lists/oss-security/2024/07/23/3ghsaWEB
- github.com/apache/arrow-rs/commit/4978e32654235f569062f2cad6c7361e410f1254ghsaWEB
- github.com/apache/arrow-rs/pull/6074ghsaWEB
- rustsec.org/advisories/RUSTSEC-2024-0358.htmlghsaWEB
News mentions
0No linked articles in our index yet.