mirror of
https://github.com/NationalSecurityAgency/ghidra.git
synced 2026-09-28 17:11:11 -09:00
Reject null signatures in GhidraServer PKI Auth
Fixes auth bypass vulnerability
This commit is contained in:
@@ -141,14 +141,14 @@ public class PKIAuthenticationModule implements AuthenticationModule {
|
|||||||
DefaultTrustManagerFactory.validateClient(certChain, PKIUtils.RSA_TYPE);
|
DefaultTrustManagerFactory.validateClient(certChain, PKIUtils.RSA_TYPE);
|
||||||
|
|
||||||
byte[] sigBytes = sigCb.getSignature();
|
byte[] sigBytes = sigCb.getSignature();
|
||||||
if (sigBytes != null) {
|
if (sigBytes == null) {
|
||||||
|
throw new FailedLoginException("Client signature required");
|
||||||
Signature sig = Signature.getInstance(certChain[0].getSigAlgName());
|
}
|
||||||
sig.initVerify(certChain[0]);
|
Signature sig = Signature.getInstance(certChain[0].getSigAlgName());
|
||||||
sig.update(token);
|
sig.initVerify(certChain[0]);
|
||||||
if (!sig.verify(sigBytes)) {
|
sig.update(token);
|
||||||
throw new FailedLoginException("Incorrect signature");
|
if (!sig.verify(sigBytes)) {
|
||||||
}
|
throw new FailedLoginException("Incorrect signature");
|
||||||
}
|
}
|
||||||
|
|
||||||
String dnUsername =
|
String dnUsername =
|
||||||
|
|||||||
Reference in New Issue
Block a user