CBL Mariner 2.0 Security Update: application-gateway-kubernetes-ingress / azcopy / cert-manager / coredns / etcd / influxdb / packer (CVE-2024-51744)

low Nessus Plugin ID 233496

Synopsis

The remote CBL Mariner host is missing one or more security updates.

Description

The version of application-gateway-kubernetes-ingress / azcopy / cert-manager / coredns / etcd / influxdb / packer installed on the remote CBL Mariner 2.0 host is prior to tested version. It is, therefore, affected by a vulnerability as referenced in the CVE-2024-51744 advisory.

- golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in dangerous situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behaviour of an established function and is not 100 % backwards compatible, so updating to 4.5.1 might break your code. In case you cannot update to 4.5.0, please make sure that you are properly checking for all errors (dangerous ones first), so that you are not running in the case detailed above. (CVE-2024-51744)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://nvd.nist.gov/vuln/detail/CVE-2024-51744

Plugin Details

Severity: Low

ID: 233496

File Name: mariner_CVE-2024-51744.nasl

Version: 1.1

Type: local

Published: 3/29/2025

Updated: 3/29/2025

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:N/AC:H/Au:N/C:P/I:N/A:N

CVSS Score Source: CVE-2024-51744

CVSS v3

Risk Factor: Low

Base Score: 3.1

Temporal Score: 2.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:microsoft:cbl-mariner:cert-manager-cmctl, p-cpe:/a:microsoft:cbl-mariner:cert-manager-cainjector, p-cpe:/a:microsoft:cbl-mariner:cert-manager-debuginfo, p-cpe:/a:microsoft:cbl-mariner:influxdb, p-cpe:/a:microsoft:cbl-mariner:coredns, x-cpe:/o:microsoft:cbl-mariner, p-cpe:/a:microsoft:cbl-mariner:etcd, p-cpe:/a:microsoft:cbl-mariner:etcd-tools, p-cpe:/a:microsoft:cbl-mariner:cert-manager, p-cpe:/a:microsoft:cbl-mariner:cert-manager-acmesolver, p-cpe:/a:microsoft:cbl-mariner:etcd-debuginfo, p-cpe:/a:microsoft:cbl-mariner:azcopy, p-cpe:/a:microsoft:cbl-mariner:packer, p-cpe:/a:microsoft:cbl-mariner:cert-manager-controller, p-cpe:/a:microsoft:cbl-mariner:application-gateway-kubernetes-ingress, p-cpe:/a:microsoft:cbl-mariner:cert-manager-webhook

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/CBLMariner/release, Host/CBLMariner/rpm-list

Exploit Ease: No known exploits are available

Patch Publication Date: 3/11/2025

Vulnerability Publication Date: 11/4/2024

Reference Information

CVE: CVE-2024-51744