2.1 LOW
- CVSS version (CVSS): 4.0
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Attack Requirement (AT): Present (P)
- Privileges Required (PR): Low (L)
- User Interaction (UI): Passive (P)
- Vulnerable System Impact Confidentiality (VC): Low (L)
- Vulnerable System Impact Integrity (VI): Low (L)
- Vulnerable System Impact Availability (VA): Low (L)
- Subsequent System Impact Confidentiality (SC): None (N)
- Subsequent System Impact Integrity (SI): None (N)
- Subsequent System Impact Availability (SA): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Attack Requirement (MAT): Present (P)
- Modified Privileges Required (MPR): Low (L)
- Modified User Interaction (MUI): Passive (P)
- Modified Vulnerable System Impact Confidentiality (MVC): Low (L)
- Modified Vulnerable System Impact Integrity (MVI): Low (L)
- Modified Vulnerable System Impact Availability (MVA): Low (L)
- Modified Subsequent System Impact Confidentiality (MSC): Negligible (N)
- Modified Subsequent System Impact Integrity (MSI): Negligible (N)
- Modified Subsequent System Impact Availability (MSA): Negligible (N)
- Safety (S): Not Defined (X)
- Automatable (AU): Not Defined (X)
- Recovery (R): Not Defined (X)
- Value Density (V): Not Defined (X)
- Vulnerability Response Effort (RE): Not Defined (X)
- Provider Urgency (U): Not Defined (X)
- Confidentiality Req. (CR): Not Defined (X)
- Integrity Req. (IR): Not Defined (X)
- Availability Req. (AR): Not Defined (X)
- Exploit Maturity (E): Not Defined (X)
Activity log
- Created suggestion
kas checks out SHA-like git branches as valid commits
kas is a setup tool for bitbake based projects. Prior to version 5.3, when relying solely on a git commit ID (SHA-1 or SHA-256) to qualify if a checkout of a repository is equivalent to the state validated while adding its commit ID to a kas configuration, users may be tricked to check out a branch of the same name from this repository. This implies that the referenced repository has been taken over by an attacker and modified to carry such a branch. SHA-1 commits may also be replaced by creating hash collisions, so the primary impact of this issue is on SHA-256 commit IDs. Version 5.3 fixes the issue. As a workaround, avoid relying solely on the commit ID for integrity validation of a repository that might become under control of a malicious 3rd party. If available, additional validate cryptographically signed commits or tags. Alternatively, mirror the repository to a save place, validate its integrity, and use this instead of the original one.
References
Affected products
- ==< 5.3
Matching in nixpkgs
pkgs.kas
Setup tool for bitbake based projects
pkgs.kakasi
Kanji Kana Simple Inverter
pkgs.kasasa
Snip and pin useful information to a small floating window
pkgs.jackass
VST plugin that provides JACK-MIDI support for VST hosts
pkgs.kasmweb
Streaming containerized apps and desktops to end-users
pkgs.kassert
Karlsruhe assertion library for C++
pkgs.omekasy
Command line application that converts alphanumeric characters to various styles defined in Unicode
pkgs.gitlab-kas
Kubernetes Agent (Gitlab side)
pkgs.kdePackages.kasts
Kirigami-based podcast player
pkgs.lohit-fonts.kashmiri
Free and open source fonts for Indian languages (Kashmiri)
pkgs.python313Packages.pykakasi
Python converter for Japanese Kana-kanji sentences into Kana-Roman
pkgs.python314Packages.pykakasi
Python converter for Japanese Kana-kanji sentences into Kana-Roman
pkgs.python313Packages.kasa-crypt
Fast kasa crypt
pkgs.python314Packages.kasa-crypt
Fast kasa crypt
pkgs.python313Packages.python-kasa
Python API for TP-Link Kasa Smarthome products
pkgs.python314Packages.python-kasa
Python API for TP-Link Kasa Smarthome products
pkgs.perlPackages.MooseXMarkAsMethods
Mark overload code symbols as methods
Package maintainers
-
@leona-ya Leona Maroni <nix@leona.is>
-
@l1npengtul l1npengtul <l1npengtul@l1npengtul.lol>
-
@PowerUser64 Blake North <blakelysnorth@gmail.com>
-
@bachp Pascal Bach <pascal.bach@nextrem.ch>
-
@yajo Jairo Llopis <yajo.sk8@gmail.com>
-
@s1341 Shmarya Rubenstein <s1341@shmarya.net>
-
@qbisi qbisicwate <qbisicwate@gmail.com>
-
@LunNova Luna Nova <nixpkgs-maintainer@lunnova.dev>
-
@nyanloutre Paul Trehiou <paul@nyanlout.re>
-
@mjm Matt Moriarity <matt@mattmoriarity.com>
-
@FRidh Frederik Rietdijk <fridh@fridh.nl>
-
@SuperSandro2000 Sandro Jäckel <sandro.jaeckel@gmail.com>
-
@bkchr Bastian Köcher <nixos@kchr.de>
-
@K900 Ilya K. <me@0upti.me>
-
@ilya-fedin Ilya Fedin <fedin-ilja2010@ya.ru>
-
@peterhoeg Peter Hoeg <peter@hoeg.com>
-
@NickCao Nick Cao <nickcao@nichi.co>
-
@Mathnerd314 Mathnerd314 <mathnerd314.gph+hs@gmail.com>
-
@jcaesar Julius Michaelis
-
@fabaff Fabian Affolter <mail@fabian-affolter.ch>