Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 777780 (CVE-2021-20077) - <net-analyzer/nessus-agent-bin-8.2.3: token leakage (CVE-2021-20077)
Summary: <net-analyzer/nessus-agent-bin-8.2.3: token leakage (CVE-2021-20077)
Status: RESOLVED FIXED
Alias: CVE-2021-20077
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://www.tenable.com/security/tns-...
Whiteboard: ~4 [noglsa]
Keywords:
Depends on:
Blocks:
 
Reported: 2021-03-22 21:51 UTC by John Helmert III
Modified: 2021-03-23 12:32 UTC (History)
2 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-03-22 21:51:28 UTC
CVE-2021-20077:

Nessus Agent versions 7.2.0 through 8.2.2 were found to inadvertently capture the IAM role security token on the local host during initial linking of the Nessus Agent when installed on an Amazon EC2 instance. This could allow a privileged attacker to obtain the token.


Please bump to 8.2.3.
Comment 1 Larry the Git Cow gentoo-dev 2021-03-23 09:19:30 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=8d311b29437f0162a0e6e51b0571fcc7e0fb5ef5

commit 8d311b29437f0162a0e6e51b0571fcc7e0fb5ef5
Author:     Marek Szuba <marecki@gentoo.org>
AuthorDate: 2021-03-23 09:10:39 +0000
Commit:     Marek Szuba <marecki@gentoo.org>
CommitDate: 2021-03-23 09:10:39 +0000

    net-analyzer/nessus-agent-bin: bump to 8.2.3
    
    Addresses CVE-2021-20077.
    
    Bug: https://bugs.gentoo.org/777780
    Signed-off-by: Marek Szuba <marecki@gentoo.org>

 net-analyzer/nessus-agent-bin/Manifest                                  | 2 +-
 .../{nessus-agent-bin-8.2.1.ebuild => nessus-agent-bin-8.2.3.ebuild}    | 0
 2 files changed, 1 insertion(+), 1 deletion(-)
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2021-03-23 12:32:37 UTC
Thank you! Tree is clean, all done.