目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2022-23653— B2_Command_Line_Tool 安全漏洞

一分钟漏洞结论

影响对象
Backblaze B2_Command_Line_Tool
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

B2_Command_Line_Tool是一个命令行工具,可让您轻松访问 B2 Cloud Storage 的所有功能。 B2_Command_Line_Tool 存在安全漏洞,该漏洞源于通过使用时间检查时间 (TOCTOU) 来造成竞争条件漏洞。

CVSS 4.7 · Medium EPSS 0.21% · P11
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2022-23653 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
B2 Command Line Tool TOCTOU application key disclosure
来源: CVE Program / CVE List V5
Vulnerability Description
B2 Command Line Tool is the official command line tool for the backblaze cloud storage service. Linux and Mac releases of the B2 command-line tool version 3.2.0 and below contain a key disclosure vulnerability that, in certain conditions, can be exploited by local attackers through a time-of-check-time-of-use (TOCTOU) race condition. The command line tool saves API keys (and bucket name-to-id mapping) in a local database file (`$XDG_CONFIG_HOME/b2/account_info`, `~/.b2_account_info` or a user-defined path) when `b2 authorize-account` is first run. This happens regardless of whether a valid key is provided or not. When first created, the file is world readable and is (typically a few milliseconds) later altered to be private to the user. If the directory is readable by a local attacker and the user did not yet run `b2 authorize-account` then during the brief period between file creation and permission modification, a local attacker can race to open the file and maintain a handle to it. This allows the local attacker to read the contents after the file after the sensitive information has been saved to it. Users that have not yet run `b2 authorize-account` should upgrade to B2 Command-Line Tool v3.2.1 before running it. Users that have run `b2 authorize-account` are safe if at the time of the file creation no other local users had read access to the local configuration file. Users that have run `b2 authorize-account` where the designated path could be opened by another local user should upgrade to B2 Command-Line Tool v3.2.1 and remove the database and regenerate all application keys. Note that `b2 clear-account` does not remove the database file and it should not be used to ensure that all open handles to the file are invalidated. If B2 Command-Line Tool cannot be upgraded to v3.2.1 due to a dependency conflict, a binary release can be used instead. Alternatively a new version could be installed within a virtualenv, or the permissions can be changed to prevent local users from opening the database file.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
来源: CVE Program / CVE List V5
Vulnerability Type
检查时间与使用时间(TOCTOU)的竞争条件
来源: CVE Program / CVE List V5
Vulnerability Title
B2_Command_Line_Tool 安全漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
B2_Command_Line_Tool是一个命令行工具,可让您轻松访问 B2 Cloud Storage 的所有功能。 B2_Command_Line_Tool 存在安全漏洞,该漏洞源于通过使用时间检查时间 (TOCTOU) 来造成竞争条件漏洞。
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商 产品 影响版本 CPE 订阅
Backblaze B2_Command_Line_Tool < 3.2.1 -

二、漏洞 CVE-2022-23653 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2022-23653 的情报信息

登录查看更多情报信息。

CVE-2022-23653 补丁与修复 (1)

CVE-2022-23653 厂商安全公告 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-23653

暂无评论


发表评论