Coder allows organizations to provision remote development environments via Terraform. In versions prior tp 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3, `azureidentity.Validate()` verifies that the PKCS#7 signer certificate chains to a trusted Azure CA but never verifies the PKCS#7 signature itself. An attacker can embed a legitimate Azure certificate alongside arbitrary content e.g. `{"vmId":"<target>"}` and the forged `vmId` will be accepted returning the victim workspace agent's session token. No authentication is required. The attacker only needs to know a target VM's `vmId` which is a `UUIDv4`. That's a practical limitation which would typically require prior access to be exploited. Versions 2.24.5, 2.29.13, 2.30.8, 2.31.12, 2.32.2, and 2.33.3 patch the issue. As a workaround, reconfigure any Azure templates to use token authentication rather than `azure-instance-identity`.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.24.5CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.29.0, < 2.29.13CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.30.0, < 2.30.8CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.31.0, < 2.31.12CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* | ||
>= 2.32.0, < 2.32.2CPE matchmatch criteria | cpe:2.3:a:coder:coder:*:*:*:*:*:go:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.