Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-id: <3453F677-D2AF-4149-A188-FF997B43EB20@me.com>
Date: Sun, 15 Dec 2013 09:38:20 -0500
From: "Larry W. Cashdollar" <larry0@...com>
To: "oss-security@...ts.openwall.com" <oss-security@...ts.openwall.com>
Subject: Re: Bio Basespace SDK 0.1.7 Ruby Gem exposes API Key via command line

Hello Folks,

I have been admonished off list to request a CVE number for this vulnerability.  May I have one assigned at your convenience.

Thanks!
Larry C$
  

On Dec 14, 2013, at 5:31 PM, Larry W. Cashdollar <larry0@...com> wrote:

> Title: Bio Basespace SDK 0.1.7 Ruby Gem exposes API Key via command line
> 
> Date: 11/15/2013
> 
> Author: Larry W. Cashdollar, @_larry0
> 
> Download: http://rubygems.org/gems/bio-basespace-sdk
> 
> Description:
> "BaseSpace Ruby SDK is a Ruby based Software Development Kit to be used in the development of Apps and scripts for working with Illumina's BaseSpace cloud-computing solution for next-gen sequencing data analysis. The primary purpose of the SDK is to provide an easy-to-use Ruby environment enabling developers to authenticate a user, retrieve data, and upload data/results from their own analysis to BaseSpace."
> 
> Vulnerability: The API client code passes the API_KEY to a curl command.  This exposes the api key to the shell and process table.  Another user on the system could snag the api key by just monitoring the process table. 
> 
> In the following code snippet:
> 
> bio-basespace-sdk-0.1.7/lib/basespace/api/api_client.rb
>  # +headers+:: Header of the PUT call.
>  # +trans_file+:: Path to the file that should be transferred.
>  def put_call(resource_path, post_data, headers, trans_file)
>    return %x(curl -H "x-access-token:#{@..._key}" -H "Content-MD5:#{headers['Content-MD5'].strip}" -T "#{trans_file}" -X PUT #{resource_path})
>  end
> 
> 
> Vendor: Notified 11/15/2013
> 
> Advisory: http://www.vapid.dhs.org/advisories/bio-basespace-sdk.html

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.