Horizon Alert
Summary of the vulnerability and why it matters
An HTTP header injection vulnerability in ADM's start-page-loader.cgi could allow attackers to read sensitive files from the host system. This issue affects certain versions of ADM and is accessible remotely without authentication.
- Unauthenticated attackers can read sensitive files.
- Affects ADM systems, potentially internet-facing.
- Confirm relevance and check system exposure.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit a vulnerability in the ADM web interface by sending a specially crafted HTTP request. This request leverages the `state` parameter to inject malicious headers, which in turn tricks the web server's X-Sendfile mechanism into reading and returning arbitrary files from the host system. This allows the attacker to access sensitive information without needing any credentials.
- Attacker can send malicious HTTP request.
- Vulnerability is triggered via the `state` parameter.
- Risk is reading arbitrary files from the host.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote attacker could read arbitrary files on the host system by sending a crafted HTTP request. This is possible when the underlying web server's X-Sendfile mechanism is leveraged via the `state` parameter.
- Arbitrary host system files.
- Crafted HTTP request with injected headers.
- Disclosure of sensitive host system files.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in ADM's start-page-loader.cgi, allowing unauthenticated remote attackers to read arbitrary files, likely impacts system owners and platform teams responsible for the ADM deployment. The first practical step is to identify all ADM systems, determine their exposure to the internet, and confirm their business criticality to prioritize remediation efforts.
- System owners must own the fix.
- Verify internet-facing ADM deployments.
- Plan remediation based on risk.