Skip to main content
Anthony_E
Staff
Staff
November 12, 2024

Technical Tip: JAZZ-176: Visible third-party credentials

  • November 12, 2024
  • 0 replies
  • 122 views
Description This article discusses JAZZ-176: Visible third-party credentials.
Scope FortiDLP.
Solution

Release Date:

24th April, 2019

 

Overview:

An authenticated operator with permission to view or edit third-party integrations or view webhooks could retrieve secret credential configuration via the Jazz API or web interface using browser dev tools. An operator tasked with configuring these services may be trusted with the credentials while a second operator with the same permissions may not be.

 

Affected Products:

  • Jazz Infrastructure versions 3.0.0 - 4.0.9 inclusive.

 

Unaffected Products:

  • All Jazz Agents, and Jazz Infrastructure after 4.0.9.

 

Resolution:

This issue is now mitigated in Jazz Infrastructure version 4.0.10.

 

It is strongly recommended that all on-premise installations running an affected version upgrade to the latest release as soon as possible. Releases are available to download through the support portal. Jazz Cloud customers have already been upgraded to the latest version and do not need to take any action.

 

If it is not possible to upgrade immediately, disable temporarily third-party integrations, delete webhooks from the Jazz Infrastructure, or revoke operator permissions to view third-party integration and webhook configuration details.

In 4.0.9, create a role using the Jazz API via api/v1/roles removing the permissions CAN_READ_WEBHOOKS and CAN_READ_INTEGRATION_CONFIG and assign the role to operators using the LDAP configuration interface or the internal operators API.

 

Vulnerability Information:

JAZZ-176 allows any operator with the relevant permissions to view third-party integration and webhook credentials.

Possession of these credentials allows an operator to access those third parties as if they were the Jazz Infrastructure.

Depending on the privileges granted by the credentials, this could allow an attacker to read and write sensitive information held by the third party:

 

Jazz Networks recommends that all third-party integrations and webhook credentials provide only the minimum required privileges. Consult the documentation for the recommended settings.

 

Acknowledgments:

the issue was found internally by Jazz Networks.

 

Disclosure Timeline:

  • 17/04/2019 Issue found internally by Jazz.
  • 17/04/2019 Root cause established and workarounds found.
  • 17/04/2019 Fix identified.
  • 26/04/2019 Patched Jazz Infrastructure released.
  • 26/04/2019 Vulnerability publicly disclosed.
Thought Leadership Security Summit. Outpace New Threats with AI - enhanced defense. Tuesday, Septmeber 15, 8:30 AM - 2:30 PM PT. The Golf Club at Newcastle, WA.
Fortinet Flag the Hack. Wednesday, August 26, 9:00 AM - 5:00 PM ET, COSM, Atlanta, GA.