Technical Tip: JAZZ-176: Visible third-party credentials
| Description | This article discusses JAZZ-176: Visible third-party credentials. |
| Scope | FortiDLP. |
| Solution | Release Date: 24th April, 2019
Overview: An authenticated operator with permission to view or edit third-party integrations or view webhooks could retrieve secret credential configuration via the Jazz API or web interface using browser dev tools. An operator tasked with configuring these services may be trusted with the credentials while a second operator with the same permissions may not be.
Affected Products:
Unaffected Products:
Resolution: This issue is now mitigated in Jazz Infrastructure version 4.0.10.
It is strongly recommended that all on-premise installations running an affected version upgrade to the latest release as soon as possible. Releases are available to download through the support portal. Jazz Cloud customers have already been upgraded to the latest version and do not need to take any action.
If it is not possible to upgrade immediately, disable temporarily third-party integrations, delete webhooks from the Jazz Infrastructure, or revoke operator permissions to view third-party integration and webhook configuration details. In 4.0.9, create a role using the Jazz API via api/v1/roles removing the permissions CAN_READ_WEBHOOKS and CAN_READ_INTEGRATION_CONFIG and assign the role to operators using the LDAP configuration interface or the internal operators API.
Vulnerability Information: JAZZ-176 allows any operator with the relevant permissions to view third-party integration and webhook credentials. Possession of these credentials allows an operator to access those third parties as if they were the Jazz Infrastructure. Depending on the privileges granted by the credentials, this could allow an attacker to read and write sensitive information held by the third party:
Jazz Networks recommends that all third-party integrations and webhook credentials provide only the minimum required privileges. Consult the documentation for the recommended settings.
Acknowledgments: the issue was found internally by Jazz Networks.
Disclosure Timeline:
|
