Skip to main content

Serious Java vulnerability lets hackers masquerade as anyone they please

Oracle has patched a nasty vulnerability in the Java framework, the severity of which cannot be overstated, security experts say.

Tracked as CVE-2022-21449, the flaw was found in the company’s Elliptic Curve Digital Signature Algorithm (ECDSA) for Java 15 and newer. It allows threat actors to fake TSL certificates and signatures, two-factor authentication codes, authorization credentials and the like. 

As explained by ArsTechnica, ECDSA is an algorithm that digitally authenticates messages. As it generates keys, it’s often used in standards such as FIDO’s two-factor authentication, the Security Assertion Markup Language, OpenID, and JSON. 

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

Forging SSL certificates and handshakes

The vulnerability was first discovered by Neil Madden of ForgeRock, who compared the exploit to the blank identity card from sci-fi series Doctor Who. In the series, the person looking at the ID card sees whatever the holder wants them to see, despite the fact that the card is blank.

“It turns out that some recent releases of Java were vulnerable to a similar kind of trick, in the implementation of widely-used ECDSA signatures,” Madden explained. 

“If you are running one of the vulnerable versions then an attacker can easily forge some types of SSL certificates and handshakes (allowing interception and modification of communications), signed JWTs, SAML assertions or OIDC id tokens, and even WebAuthn authentication messages. All using the digital equivalent of a blank piece of paper.”

The flaw has received an official severity score of 7.5/10, but Madden disagrees strongly with the assessment.

“It’s hard to overstate the severity of this bug. If you are using ECDSA signatures for any of these security mechanisms, then an attacker can trivially and completely bypass them if your server is running any Java 15, 16, 17, or 18 version before the April 2022 Critical Patch Update (CPU). For context, almost all WebAuthn/FIDO devices in the real world (including Yubikeys use ECDSA signatures and many OIDC providers use ECDSA-signed JWTs," he said.

Allegedly, only Java versions 15 and newer are affected, although Oracle also listed versions 7,8, and 11, as vulnerable. Still, all customers are urged to update their endpoints to the newest version.

Via ArsTechnica



Source: TechRadar

Popular posts from this blog

Twitter has hidden the chronological feed on iOS again – and I'm furious

In a controversial move, Twitter has brought back a feature that removes the 'Latest Tweets' view for users on iOS, which is something that many users, including me, hated back in March 2022 – and it's now rolling out. The first time the company decided to do this, 'Home' would appear first in a tab at the top, and there was no way of changing it so that 'Latest Tweets' would be the default view. It was reverted back after the company said it was a 'bug' for iOS users. This time though, it's no bug. Instead, it's 'For You' and 'Following' where you can only swipe between them now, which doesn't make much sense for a platform where you're using the platform to keep up to date with who you follow. It's a bizarre change that makes me ask – who wants this, especially during a time when its new owner, Elon Musk, is bringing in and reversing changes almost every week still? This one change will have big consequenc

This new Linux malware floods machines with cryptominers and DDoS bots

Cybersecurity researchers have spotted a new Linux malware downloader that targets poorly defended Linux servers with cryptocurrency miners and DDoS IRC bots. Researchers from ASEC discovered the attack after the Shell Script Compiler (SHC) used to create the downloader was uploaded to VirusTotal. Apparently, Korean users were the ones uploading the SHC, and it’s Korean users who are targets, as well. Further analysis has shown that the threat actors are going after poorly defended Linux servers, brute-forcing their way into administrator accounts over SSH.  Mining Monero Once they make their way in, they’ll either install a cryptocurrency miner, or a DDoS IRC bot. The miner being deployed is XMRig, arguably the most popular cryptocurrency miner among hackers. It uses the computing power of a victim's endpoints to generate Monero, a privacy-oriented cryptocurrency whose transactions are seemingly impossible to track, and whose users are allegedly impossible to identify. Fo

New MacBook Pro Reviews: Hands-On Look at Performance and Upgraded Specs

The new 14-inch and 16-inch MacBook Pro models will start arriving to customers and launch in stores this Tuesday. Ahead of time, the first reviews of the laptops have been shared by select media publications and YouTube channels. Powered by Apple's latest M2 Pro and M2 Max chips, the new MacBook Pros offer up to 20% faster performance and up to 30% faster graphics. The laptops can be configured with up to 96GB of RAM, compared to a max of 64GB previously. Other improvements include Wi-Fi 6E, an upgraded HDMI 2.1 port with support for up to an 8K external display, and an extra hour of battery life over the previous generation. The new MacBook Pros have the same design as the previous models released in October 2021. The laptops can be pre-ordered on Apple's online store, with pricing starting at $1,999 for the 14-inch model and at $2,499 for the 16-inch model. Benchmarks Geekbench results from last week revealed that the M2 Pro and M2 Max chips offer up to around 20%

iPhone 15 Pro Rumored to Feature Ultra-Thin Curved Bezels

The iPhone 15 Pro models will have thinner, curved bezels compared to the iPhone 14 Pro models, potentially resulting in an Apple Watch-like appearance, according to the leaker known as " ShrimpApplePro ." ShrimpApplePro clarified that the next-generation "Pro" iPhone models will still have flat displays, since only the bezels are to be curved. According to a source speaking to the leaker, this combination of slimmer bezels and curved edges could result in a look similar to the Apple Watch Series 7 and Series 8. The curved front glass will purportedly also be present on the ‌iPhone 15‌ and ‌iPhone 15‌ Plus's design, but these devices will not have thinner bezels compared to their iPhone 14 predecessors. ShrimpApplePro added that the ‌iPhone 15‌ lineup will feature the same display sizes as last year's ‌iPhone 14‌ lineup. Last year, the leaker was among the first to say that the ‌iPhone 15‌ Pro models will have a titanium frame with curved rear ed