Summary
When a client is configured with a namespace, a request that hits a transient network error (a timeout, or a connection that memcached or a proxy closed, such as stale connections after a memcached restart) is retried with the namespace applied a second time. Client#perform replaces its key argument with the validated, namespaced key and then uses retry, which re-runs the method with the already-namespaced key, so app:x becomes app:app:x.
Impact
- A read returns the value of a different key:
get('x') returned the value stored under app:app:x. Where cache keys include user input, a user who can choose a key of the form app:<something> can arrange for another user's retried read to return attacker-chosen data, or read data meant for another key.
- A write lands on a different key, overwriting it.
Affected
- 5.0.3 and later: every single-key operation (
get, set, add, replace, delete, incr, decr, touch, gat, cas, append, prepend, ...).
- 5.1.0 and later: single-server
get_multi.
- 4.1.0 and later, including all of 5.x:
get_with_metadata and fetch_with_lock.
- Clients without a
namespace are not affected. 3.2.x is not affected.
Fix
Every attempt now starts from the caller's key. Fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7.
Summary
When a client is configured with a
namespace, a request that hits a transient network error (a timeout, or a connection that memcached or a proxy closed, such as stale connections after a memcached restart) is retried with the namespace applied a second time.Client#performreplaces itskeyargument with the validated, namespaced key and then usesretry, which re-runs the method with the already-namespaced key, soapp:xbecomesapp:app:x.Impact
get('x')returned the value stored underapp:app:x. Where cache keys include user input, a user who can choose a key of the formapp:<something>can arrange for another user's retried read to return attacker-chosen data, or read data meant for another key.Affected
get,set,add,replace,delete,incr,decr,touch,gat,cas,append,prepend, ...).get_multi.get_with_metadataandfetch_with_lock.namespaceare not affected. 3.2.x is not affected.Fix
Every attempt now starts from the caller's key. Fixed in 5.2.2, 5.1.4, 5.0.10 and 4.3.7.