CVE-2018-12088
Last modified
CVE-2018-12088 is a vulnerability of currently unknown severity. S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.. EPSS estimates a 1.88% chance of exploitation in the next 30 days.
Description
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or temporarily hide parts of files. This is related to the checksum_basic_mapping function.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| S3ql Project | S3ql | < 2.27 |
References
- https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020Patch, Third Party Advisory
- https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-failsExploit, Third Party Advisory
- https://bitbucket.org/nikratio/s3ql/commits/85aba5c2d5c81453a73a50ed638adaeef0521020Patch, Third Party Advisory
- https://bitbucket.org/nikratio/s3ql/issues/272/t3_verifypy-test_retrieve-sometimes-failsExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12088?
How severe is CVE-2018-12088?
How do I fix CVE-2018-12088?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12082The mintToken function of a smart contract implementation fo…
- CVE-2018-12083The mintToken function of a smart contract implementation fo…
- CVE-2018-12084The mintToken function of a smart contract implementation fo…
- CVE-2018-12085Liblouis 3.6.0 has a stack-based Buffer Overflow in the func…
- CVE-2018-12086Buffer overflow in OPC UA applications allows remote attacke…
- CVE-2018-12087Failure to validate certificates in OPC Foundation UA Client…
- CVE-2018-12089In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with …
- CVE-2018-1209Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2018-12090There is unauthenticated reflected cross-site scripting (XSS…
- CVE-2018-12092tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::…
- CVE-2018-12093tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory …
- CVE-2018-12094Cross-site scripting (XSS) vulnerability in news.php in Dimo…
Are you affected by CVE-2018-12088?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
