DEV Community

Mark0
Mark0

Posted on

harness(gitness) registry webhook sort_order blind SQL injection

A blind SQL injection vulnerability has been discovered in Harness (Gitness), an open-source platform for source control and artifact registries. The flaw is located in the registry webhook listing API, specifically within the sort_order query parameter. Due to a lack of normalization in a specific code path, raw query-string bytes are interpolated directly into an SQL ORDER BY clause, bypassing existing security guards used in other parts of the application.

The vulnerability allows authenticated users with registry view permissions to perform blind data extraction from the database. A critical risk is the exfiltration of the principal_salt, which can be used to forge JWT session tokens and potentially gain administrative access. The recommended solution involves implementing strict allowlists for sorting parameters at both the controller and DAO levels to ensure only valid 'ASC' or 'DESC' values are processed.


Read Full Article

Top comments (0)