Horizon Alert
Summary of the vulnerability and why it matters
An improper authentication vulnerability exists in FalkorDB's Bolt endpoint, potentially allowing unauthenticated remote attackers to execute graph queries. This issue arises from how the system handles authentication errors, incorrectly treating certain operational errors as successful authentication. While the Bolt endpoint is disabled by default, its enablement would expose this vulnerability.
- Unauthenticated access to graph queries.
- Enables unauthorized data interaction.
- Confirm relevance and assess exposure.
Attack Path
How an attacker could exploit the issue
An attacker can remotely send unauthenticated requests to FalkorDB's Bolt endpoint if it is enabled. The system incorrectly assumes authentication based on certain network or loading errors when it should require proper credentials, allowing the attacker to execute graph queries.
- Network access to enabled Bolt endpoint.
- Empty AUTH command triggers misauthentication.
- Unauthenticated graph query execution.
Live Threat
Current exploitation, exposure, and threat context
When the Bolt endpoint is enabled, an unauthenticated remote attacker could execute arbitrary graph queries by exploiting an improper authentication flaw in the `is_authenticated` function. This could occur during specific conditions such as dataset loading, replication failover, or when the system is under memory pressure, which can cause the function to incorrectly identify the attacker as authenticated.
- Graph queries could be executed.
- Flawed authentication logic is exploited.
- Unauthorized system access may occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts FalkorDB deployments that have enabled the Bolt endpoint. Initial triage should focus on identifying these deployments, assessing their exposure and criticality, and confirming the accountable owner within the platform or infrastructure teams. Remediation planning should then be prioritized based on this risk assessment.
- Identify Bolt endpoint usage and ownership.
- Verify business criticality and network exposure.
- Plan remediation based on risk and impact.