Skip to content

Hardening: gate monitoring-template creation and restrict script/ssh collect protocols for non-admin users #4382

Description

@Baymax-armed

Background

Authoring a monitoring type via POST /api/apps/define/yml is available to the non-admin user role (/api/apps/**===post===[admin,user] in sureness.yml). A template can set protocol: script with an arbitrary scriptCommand, which ScriptCollectImpl.collect runs via new ProcessBuilder("bash","-c", scriptCommand) (hertzbeat-collector-basic/.../collect/script/ScriptCollectImpl.java:81). The import-time guard RISKY_STR_ARR (hertzbeat-manager/.../controller/AppController.java:55-59) only blocks Java/Groovy/deserialization tokens, and verifyDefineAppContent validates structure only, so a shell command passes; it can then be run synchronously via POST /api/monitor/detect.

I reported this privately to the ASF security team. They assessed it as within the documented trusted-user security model (roles are not a security boundary — "all users have management permissions"), so it is not a vulnerability, and suggested raising it here as a hardening improvement aligned with the role-enforcement work planned for 1.9.0.

Suggested hardening

  • Gate POST /api/apps/define/yml to admin (matching PUT/DELETE), or under the upcoming role enforcement.
  • Allowlist the collect protocol accepted in user-authored templates (exclude script/ssh/command protocols), validated at import.
  • Shell-escape (or strictly allowlist) ^_^param^_^ substitutions before they enter a command.

Happy to send a PR if this direction sounds right.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions