Skip to content

[SECURITY] Unauthenticated Access + Debug RCE - Responsible Disclosure #8

Description

@Krtt-80v6

Hi @alonz22,

I found two security vulnerabilities in haproxy-dashboard v1.3.4.
I'm reporting this responsibly to give you time to fix before public disclosure.

Vulnerability 1 — Missing Authentication (CWE-306) — High
/statistics and /logs are accessible without any authentication.

Vulnerability 2 — Werkzeug Debugger Exposed (CWE-489) — Critical
debug=True on host='::' exposes the interactive debugger publicly.
This allows Remote Code Execution on the server.

Please fix and I will request a CVE with your coordination.

Researcher: Ali Mohammed Kadhim

Image Image

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions