CVE-2024-21491
Last modified
CVE-2024-21491 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Versions of the package svix before 1.17.0 are vulnerable to Authentication Bypass due to an issue in the verify function where signatures of different lengths are incorrectly compared. An attacker can bypass signature verification by providing a shorter signature that matches the beginning of the actual signature. **Note:** The attacker would need to know a victim uses the Rust library for verification,no easy way to automatically check that; and uses webhooks by a service that uses Svix, and then figure out a way to craft a malicious payload that will actually include all of the correct identifiers needed to trick the receivers to cause actual issues.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Svix | Svix-Webhooks | < 1.17.0 |
References
- https://rustsec.org/advisories/RUSTSEC-2024-0010.htmlThird Party Advisory
- https://security.snyk.io/vuln/SNYK-RUST-SVIX-6230729Third Party Advisory
- https://rustsec.org/advisories/RUSTSEC-2024-0010.htmlThird Party Advisory
- https://security.snyk.io/vuln/SNYK-RUST-SVIX-6230729Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-21491?
How severe is CVE-2024-21491?
How do I fix CVE-2024-21491?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-21484Versions of the package jsrsasign before 11.0.0 are vulnerab…5.9
- CVE-2024-21485Versions of the package dash-core-components before 2.13.0; …5.4
- CVE-2024-21488Versions of the package network before 0.7.0 are vulnerable …9.8
- CVE-2024-21489Versions of the package uplot before 1.6.31 are vulnerable t…8.2
- CVE-2024-2149A vulnerability classified as critical was found in CodeAstr…7.2
- CVE-2024-21490This affects versions of the package angular from 1.3.0; ver…7.5
- CVE-2024-21492All versions of the package github.com/greenpau/caddy-securi…8.1
- CVE-2024-21493All versions of the package github.com/greenpau/caddy-securi…5.3
- CVE-2024-21494All versions of the package github.com/greenpau/caddy-securi…5.4
- CVE-2024-21495Versions of the package github.com/greenpau/caddy-security b…9.8
- CVE-2024-21496All versions of the package github.com/greenpau/caddy-securi…6.1
- CVE-2024-21497Versions of the package github.com/greenpau/caddy-security …6.1
Are you affected by CVE-2024-21491?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
