NethermindEth / NethermindEth/Catalyst

Verify the state of rsa dependency - security alert

Open
#735 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Rust
Stars
44
Forks
18
PR merge metrics
No merged PRs in 30d

Description

We can ignore it for now, but we'll need to check for a newer version again in a while.

error[vulnerability]: Marvin Attack: potential key recovery through timing sidechannels
    ┌─ /home/maciej/dev/nethermind/taiko/Catalyst/Cargo.lock:646:1
    │
646 │ rsa 0.9.8 registry+https://github.com/rust-lang/crates.io-index
    │ ━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━ security vulnerability detected
    │
    ├ ID: RUSTSEC-2023-0071
    ├ Advisory: https://rustsec.org/advisories/RUSTSEC-2023-0071
    ├ ### Impact
      Due to a non-constant-time implementation, information about the private key is leaked through timing information which is observable over the network. An attacker may be able to use that information to recover the key.
      
      ### Patches
      No patch is yet available, however work is underway to migrate to a fully constant-time implementation.
      
      ### Workarounds
      The only currently available workaround is to avoid using the `rsa` crate in settings where attackers are able to observe timing information, e.g. local use on a non-compromised computer is fine.
      
      ### References
      This vulnerability was discovered as part of the "[Marvin Attack]", which revealed several implementations of RSA including OpenSSL had not properly mitigated timing sidechannel attacks.
      
      [Marvin Attack]: https://people.redhat.com/~hkario/marvin/
    ├ Announcement: https://github.com/RustCrypto/RSA/issues/19#issuecomment-1822995643
    ├ Solution: No safe upgrade is available!
    ├ rsa v0.9.8
      └── sqlx-mysql v0.8.6
          ├── sqlx v0.8.6
          │   └── urc v1.23.8
          │       └── permissionless v1.23.8
          └── sqlx-macros-core v0.8.6
              └── sqlx-macros v0.8.6
                  └── sqlx v0.8.6 (*)

advisories FAILED, bans ok, licenses ok, sources ok
❌ Critical: Vulnerable dependencies detected (run 'cargo deny check')
error: nie można wypchnąć niektórych referencji do „github.com:NethermindEth/Catalyst.git”

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with Catalyst/Cargo.lock:646 and run cargo deny check to confirm the RUSTSEC-2023-0071 alert for rsa 0.9.8 through sqlx-mysql. Check the current dependency and advisory status; done means recording whether a safe upgrade or other actionable resolution exists.

Written by the indexing model from the issue text.

Assessment

Tech stack
rust
Domain
build-system, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.