linuxfabrik-lib предоставляет модули Python для доступа к базе данных, кэширования, выполнения оболочки и интеграции API, а плагины мониторинга Linuxfabrik используют свой общий помощник по тестированию во всех плагинах проверки. До версий linuxfabrik-lib 6.1.0 и плагинов мониторинга Linuxfabrik 7.0.0 функция lib.lftest.test() обрабатывала первый или второй элемент CSV-аргумента --test как путь к файловой системе и возвращала содержимое файла как моделируемый стандартный вывод или стандартную ошибку без ограничения пути. Скрытый, но доступный для производства аргумент --test был принят плагинами, авторизованными sudo, поэтому злоумышленник, контролирующий учетную запись nagios или icinga, мог использовать check-plugins/deb-updates/deb-updates с QUERY=1 по умолчанию, чтобы раскрыть каждую строку файла, доступного для чтения root.
Примерно 22 других плагина раскрывали отфильтрованный контент или существование корневого файла и оракул читаемости через один и тот же помощник, в то время как check-plugins/network-bonding/network-bonding и check-plugins/openstack-swift-stat/openstack-swift-stat имели прямые пути чтения в обход помощника. Исправление библиотеки ограничивает чтение фикстуры каталогом unit-test вызывающего плагина и отклоняет небезопасные привязки, а исправление плагина направляет два обхода через этот помощник. Эти проблемы исправлены в linuxfabrik-lib 6.1.0 и плагинах мониторинга Linuxfabrik 7.0.0.
Показать оригинальное описание (EN)
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper across check plugins. Prior to linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0, lib.lftest.test() treated the first or second element of a --test CSV argument as a filesystem path and returned the file contents as simulated standard output or standard error without path confinement. The hidden but production-accessible --test argument was accepted by sudo-authorized plugins, so an attacker controlling the nagios or icinga account could use check-plugins/deb-updates/deb-updates with its default QUERY=1 to disclose every line of a root-readable file. Approximately 22 other plugins exposed filtered content or a root file existence and readability oracle through the same helper, while check-plugins/network-bonding/network-bonding and check-plugins/openstack-swift-stat/openstack-swift-stat had direct read paths that bypassed the helper. The library fix confines fixture reads to the invoking plugin's unit-test directory and refuses unsafe anchors, and the plugin fix routes the two bypasses through that helper. These issues are fixed in linuxfabrik-lib 6.1.0 and Linuxfabrik Monitoring Plugins 7.0.0.
Характеристики атаки
Последствия
Строка CVSS v3.1