Описание
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using ntlmssp.Negotiator as an HTTP transport. Version 0.1.1 patches the issue.
A flaw was found in the go-ntlmssp package (before 0.1.1). A remote attacker can send a crafted NTLM challenge message that triggers a slice out-of-bounds panic, crashing any Go process using ntlmssp.Negotiator as an HTTP transport.
Отчет
go-ntlmssp is vulnerable to denial of service in NTLM challenge parsing before version 0.1.1. When a Go process uses ntlmssp.Negotiator as an HTTP transport, a remote party can send a malformed NTLM challenge that triggers a slice out-of-bounds panic and crashes the process. Red Hat exposure is narrow: most products that transitively bundle the library (OpenShift must-gather images, CNV must-gather, cert-manager, Ceph dashboard, Ansible Automation Platform utilities) are not affected because they do not use Negotiator against untrusted NTLM endpoints; the remaining risk sits with any Go service that authenticates over HTTP via NTLM/Negotiate and accepts challenge messages from an attacker-influenced source.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Assisted Installer for Red Hat OpenShift Container Platform 2 | assisted/agent-preinstall-image-builder-rhel9 | Under investigation | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/cert-manager-istio-csr-rhel9 | Not affected | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-acmesolver-rhel9 | Not affected | ||
| cert-manager Operator for Red Hat OpenShift | cert-manager/jetstack-cert-manager-rhel9 | Not affected | ||
| Confidential Compute Attestation | openshift-sandboxed-containers/osc-must-gather-rhel9 | Under investigation | ||
| External Secrets Operator for Red Hat OpenShift | external-secrets-operator/bitwarden-sdk-server-rhel9 | Not affected | ||
| External Secrets Operator for Red Hat OpenShift | external-secrets-operator/external-secrets-operator-bundle | Not affected | ||
| External Secrets Operator for Red Hat OpenShift | external-secrets-operator/external-secrets-operator-rhel9 | Not affected | ||
| External Secrets Operator for Red Hat OpenShift | external-secrets-operator/external-secrets-rhel9 | Not affected | ||
| Kernel Module Management Operator for Red Hat Openshift | kmm/kernel-module-management-must-gather-rhel9 | Under investigation |
Показывать по
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication over HTTP. Prior to version 0.1.1, a malicious NTLM challenge message can causes an slice out of bounds panic, which can crash any Go process using `ntlmssp.Negotiator` as an HTTP transport. Version 0.1.1 patches the issue.
go-ntlmssp is a Go package that provides NTLM/Negotiate authentication ...
go-ntlmssp NTLM challenges can panic on malformed payloads
EPSS
5.3 Medium
CVSS3