github inex/IXP-Manager v7.4.1
v7.4.1 - Critical security release and other improvements

6 hours ago

INEX is pleased to announce the general availability of IXP Manager v7.4.1. This release is primarily a critical security release and all users of IXP Manager should upgrade as soon as possible. This release also contains some improvements and bug fixes.

Release Summary

git --no-pager diff --shortstat v7.4.0
 510 files changed, 12186 insertions(+), 21784 deletions(-)

Upgrade Instructions

The official upgrade instructions are here. As this is a bug-fix release, no database migrations are required.


Security

Impact: Moderate to Critical

Summary

We have released IXP Manager v7.4.1 to address 8 security vulnerabilities via the GitHub Security Advisory programme. The vulnerabilities were responsibly disclosed and, to our knowledge, have not been used in the wild.

As part of our response to these disclosures, we characterised the nature of the vulnerabilities and reviewed other areas where similar issues may occur.

In addition to the immediate fixes, we typically carry out follow-up work in a subsequent release, including but not limited to regression tests and more thorough refactoring of the affected areas.

Identified Issues

  1. Configuration injection by customer administrators via GHSA-w2p9-j8gv-xv8q. (Severity: Critical - 9.9 / 10).
    A vulnerability was reported where an authenticated user (with customer admin or super user privileges) could inject routing policy statements into the route server configuration.

  2. Password-only session can bypass 2FA via GHSA-f459-pfh4-46wf. (Severity: High - 8.8 / 10).
    A two-factor bypass vulnerability was reported, which allowed a logged-in user to bypass 2FA by visiting a specific URL.

  3. 2FA challenge not enforced on API route groups via GHSA-85w6-2whw-33hh. (Severity: High - 8.3 / 10).
    A partly logged-in user (password provided but no 2FA provided) could interact with the API with full privileges without completing the 2FA authentication stage.

  4. No rate limiting / lockout on the 2FA verification endpoint via GHSA-3g5g-hhhw-5823. (Severity: High - 7.4 / 10)
    A vulnerability was reported where an attacker has unthrottled access to the 2FA endpoint.

  5. Broken Object Level Authorisation (BOLA) allows cross-tenant contact tampering and hijacking via GHSA-vjp5-jfw9-g6vp. (Severity: High - 7.1 / 10).
    A vulnerability was reported in IXP Manager where a contact belonging to one member could be edited and placed into another member organisation.

  6. 2FA bypass via cross-account session/token binding via GHSA-5vw4-gw9f-2cmv. (Severity: Moderate - 6.6 / 10).
    A user who can log in to IXP Manager can bypass the 2FA challenge for another user if they know that user's password.

  7. Unauthenticated reflected XSS in Looking Glass via GHSA-362c-r3gq-44gw. (Severity: Moderate 6.1 / 10).
    A reflected (non-persistent) cross-site scripting vulnerability was reported in IXP Manager. An unauthenticated user may craft malicious links that, if navigated to, execute malicious JavaScript in the user's browser and may perform any action in IXP Manager that the victim user is authorised to perform.

  8. Stored XSS due to inadequate validation and unescaped output via GHSA-cqgq-hjjc-m927. (Severity: Moderate - 5.4 / 10)
    A persistent (stored) cross-site scripting vulnerability exists in IXP Manager. An authenticated user with customer admin or super user privileges can insert malicious JavaScript code into a stored field in the application.


Improvements

In this release, we migrated our frontend build system from Webpack to Vite due to deprecated support for the laravel-mix package.

Vite is a modern frontend build tool that provides an extremely fast development environment and bundles code for production. Laravel integrates seamlessly with Vite through an official plugin and a Blade directive that loads assets in both development and production.

As part of the upgrade to this build system, we upgraded FontAwesome, Tailwind, and numerous other dependencies to a recent major version.

Because we were using older versions of some NPM libraries due to being stuck on laravel-mix, some of these had development or unused code elements with security issues. A major achievement of this work is that none of our NPM dependencies now have any associated security reports.


Other Improvements

  • Add missing var to Peering Manager's notes so updates include date + username - #1103
  • Remove AppServiceProvider dead code - registrar interface/implementation doesn't exist anymore - #1102
  • User: be more robust against stale reads of currentCustomerToUser - #1101
  • User2FA: light refactoring - #1100
  • Rerun Model phpdoc generation after syncing CI and migrations schema - #1098
  • Test Listeners, and update/simplify some code in events/listeners/mail. - #1094
  • Improve logging of actions with side-effects (upload files, send emails, change route filters, etc) - #1093
  • update installer script to use x-frame-options: sameorigin - #1089
  • Phyiscal Interface deletion: if it's a core link member, refer the user to the core bundle page to manage the PI - #1087
  • Eloquent frontend: fix strange wording in templated strings - #1086
  • psalm fix: Provide types for const and static class members - #1082
    -RsFilterControllerTest: removed dialog dismiss test which occasionally errors out - #1080
  • Refactoring around bootbox for XSS resilience - #1079
  • Rebrand QA commands as unit tests - #1078#1078
  • Patch panel: add inactive field on create/edit - #1077
  • CI + vagrant DB: use data only dumps instead of full schemas - #1076
  • Unit tests to cover ixp-manager:setup-wizard - #1073
  • Fix ci_test_db.sql to use structure per migrations #1072
  • Tests namespace identified properly through composer & IDE tweaks - #1071
  • psalm fix: RegistrationCheckResult: initialize eligibleInfrastructures - #1070
  • Validator classes: psalm fixes via #1069
  • migrations (psalm fix): make migration classes final via #1068

Bug Fixes

  • BgpSessionDataAggregator: fix logic bug - #1099
  • core bundle delete: should mark switch port as unset like core-link delete does #1088
  • core bundle setup: query DOM for state instead of trying to maintain list of already used SP's - #1085
  • Basic Validator: fix incorrect directory check, improve filesystem permissons validation, and fix validation report dropdown behavior - #1083

Acknowledgements

We wish to thank everyone who contributed to this release: @T-Chachamaru, @FB-wallfacer


CI Results for this Release

PHP unit tests:

./vendor/bin/phpunit
PHPUnit 12.5.36 by Sebastian Bergmann and contributors.

Runtime:       PHP 8.4.25
Configuration: ~/dev/ixpm-inex/phpunit.xml

...............................................................  63 / 777 (  8%)
............................................................... 126 / 777 ( 16%)
............................................................... 189 / 777 ( 24%)
............................................................... 252 / 777 ( 32%)
............................................................... 315 / 777 ( 40%)
............................................................... 378 / 777 ( 48%)
............................................................... 441 / 777 ( 56%)
............................................................... 504 / 777 ( 64%)
............................................................... 567 / 777 ( 72%)
............................................................... 630 / 777 ( 81%)
............................................................... 693 / 777 ( 89%)
............................................................... 756 / 777 ( 97%)
.....................                                           777 / 777 (100%)

Time: 05:39.870, Memory: 139.00 MB

CI tests:

❯ ./vendor/bin/psalm --use-baseline=psalm-baseline.xml

Running on PHP 8.4.25, Psalm 6.19.0@0f67d9a41b903d0c205645f3b428dff1c92310e0.

JIT acceleration: OFF
You can enable JIT acceleration (experimental) with --force-jit.

Target PHP version: 8.4 (inferred from composer.json).

Scanning files...

Analyzing files...

░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░  60 / 615 (9%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 120 / 615 (19%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 180 / 615 (29%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 240 / 615 (39%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 300 / 615 (48%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 360 / 615 (58%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 420 / 615 (68%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 480 / 615 (78%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 540 / 615 (87%)
░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░░ 600 / 615 (97%)
░░░░░░░░░░░░░░░

------------------------------

       No errors found!

------------------------------

Checks took 17.39 seconds and used 1,703.392MB of memory
Psalm was able to infer types for 90.8208% of the codebase

Don't miss a new IXP-Manager release

NewReleases is sending notifications on new releases.