OPA Compiler: Bypass of WithUnsafeBuiltins using `with` keyword to mock functions
Published Sep 8, 2022
9.8
CRITICALCVSS 3.1
EPSS 1.59%
Description
Open Policy Agent (OPA) is an open source, general-purpose policy engine. The Rego compiler provides a (deprecated) `WithUnsafeBuiltins` function, which allows users to provide a set of built-in functions that should be deemed unsafe — and as such rejected — by the compiler if encountered in the policy compilation stage. A bypass of this protection has been found, where the use of the `with` keyword to mock such a built-in function (a feature introduced in OPA v0.40.0), isn’t taken into account by `WithUnsafeBuiltins`. Multiple conditions need to be met in order to create an adverse effect. Version 0.43.1 contains a patch for this issue. As a workaround, avoid using the `WithUnsafeBuiltins` function and use the `capabilities` feature instead.
Affected products
-
- Version >= 0.40.0, < 0.43.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Open-Policy-Agent | Opa | n/a |
|
- ≥ 0.40.0 · < 0.43.1
No data.
Logging Subsystem for Red Hat OpenShift
openshift-logging/lokistack-gateway-rhel8
Not affected
Logging Subsystem for Red Hat OpenShift
openshift-logging/opa-openshift-rhel8
Not affected
OpenShift Serverless
openshift-serverless-1/client-kn-rhel8
Not affected
OpenShift Service Mesh 2.0
servicemesh
Not affected
Red Hat Advanced Cluster Management for Kubernetes 2
rhacm2/gatekeeper-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-main-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-db-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-db-slim-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-rhel8
Not affected
Red Hat Advanced Cluster Security 3
advanced-cluster-security/rhacs-scanner-slim-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/cnf-tests-rhel8
Not affected
Red Hat OpenShift Container Platform 4
openshift4/ztp-site-generate-rhel8
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Logging Subsystem for Red Hat OpenShift | openshift-logging/lokistack-gateway-rhel8 | Not affected | n/a |
| Logging Subsystem for Red Hat OpenShift | openshift-logging/opa-openshift-rhel8 | Not affected | n/a |
| OpenShift Serverless | openshift-serverless-1/client-kn-rhel8 | Not affected | n/a |
| OpenShift Service Mesh 2.0 | servicemesh | Not affected | n/a |
| Red Hat Advanced Cluster Management for Kubernetes 2 | rhacm2/gatekeeper-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-main-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-db-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-db-slim-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-rhel8 | Not affected | n/a |
| Red Hat Advanced Cluster Security 3 | advanced-cluster-security/rhacs-scanner-slim-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/cnf-tests-rhel8 | Not affected | n/a |
| Red Hat OpenShift Container Platform 4 | openshift4/ztp-site-generate-rhel8 | Not affected | n/a |
github.com/open-policy-agent/opa
Go
Introduced 0.40.0 Fixed 0.44.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/open-policy-agent/opa | 0.40.0 | 0.44.0 |
Remediation
No remediation recorded yet.
References (12)
- https://access.redhat.com/security/cve/CVE-2022-36085 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2125532 Issue Tracking
- https://github.com/advisories/GHSA-f524-rf33-2jjr Advisory
- https://github.com/open-policy-agent/opa/commit/25a597bc3f4985162e7f65f9c36599f4f8f55823 x_refsource_MISCPatchThird Party Advisory
- https://github.com/open-policy-agent/opa/commit/3e8c754ed007b22393cf65e48751ad9f6457fee8 x_refsource_MISCPatchThird Party Advisory
- https://github.com/open-policy-agent/opa/pull/4540 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/open-policy-agent/opa/pull/4616 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/open-policy-agent/opa/releases/tag/v0.43.1 x_refsource_MISCThird Party Advisory
- https://github.com/open-policy-agent/opa/security/advisories/GHSA-f524-rf33-2jjr x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-36085
- https://pkg.go.dev/vuln/GO-2022-0978
- https://www.cve.org/CVERecord?id=CVE-2022-36085
Change history (0)
No recorded changes yet.