PT-2026-82818 · Npm · Ep Etherpad-Lite

Publicado

2026-08-17

·

Atualizado

2026-08-17

Nenhuma

Não há classificações de severidade ou métricas disponíveis. Quando houver, atualizaremos as informações correspondentes na página.
Fix: PR #7906 (ether/etherpad). A set of medium/low hardening fixes:
  • Weak RNG for tokens (CWE-330): author/session/readonly IDs were generated with Math.random() (client and server). Now use crypto.getRandomValues.
  • Login timing / no failure delay (CWE-208/CWE-307): the OIDC interaction login used a non-constant-time password compare with no failure delay. Now uses crypto.timingSafeEqual plus a uniform failure delay; user lookup is own-property only.
  • Plugin dependency path handling (CWE-22): plugin dependency names from package.json were used to build filesystem paths without validation (admin-gated install). Now validated against the npm name grammar.
  • API parameter pollution (CWE-235): /api/2 merged all request headers into the API field set. Now forwards only authorization, matching the openapi.ts handler.
  • Pad-creation side effect: API.appendChatMessage could create arbitrary pads (missing getPadSafe). Now requires the pad to exist.
  • Error info disclosure (CWE-209): the admin file server echoed filesystem error detail; now returns a generic message.

Generation of Error Message Containing Sensitive Information

Path traversal

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

GHSA-92HR-GMR6-H8CP

Produtos afetados

Ep Etherpad-Lite