Description
Ghidra before 12.1 contains an authentication bypass vulnerability in PKIAuthenticationModule.authenticate() that allows any user with a valid CA-signed certificate to impersonate other users by presenting their public certificate with a null signature. Attackers can escalate privileges, modify repository access controls, exfiltrate shared reverse engineering databases, and permanently compromise server integrity.
Problem types
Improper Verification of Cryptographic Signature
Product status
Any version before 12.1
12.1 (custom)
Credits
@jro-calif
Sean Nejad (@allsmog)
References
github.com/...ghidra/security/advisories/GHSA-5wxq-7qpv-65p2 (GitHub Security Advisory (GHSA-5wxq-7qpv-65p2))
github.com/...ommit/78729379e471bbb3d969409be6a8c3d24af84220 (Patch Commit (1))
github.com/...ommit/79d8f164f8bb8b15cfb60c5d4faeb8e1c25d15ca (Patch Commit (2))
www.vulncheck.com/...ll-signature-in-pkiauthenticationmodule