Horizon Alert
Summary of the vulnerability and why it matters
A security issue has been identified in Percona Monitoring and Management software that could allow an attacker with administrative access to execute commands on the underlying operating system. This vulnerability stems from an internal database user retaining excessive privileges, which can be exploited through a specific feature designed for adding data sources. At a high level, this could potentially compromise the integrity and confidentiality of systems managed by PMM if not addressed.
- Database oversight allows command execution.
- Impacts systems managing critical data.
- Confirm relevance and assess potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker with administrative rights on Percona Monitoring and Management can exploit a vulnerability by using the "Add data source" feature. This allows them to escape the database environment and run commands on the server's operating system.
- Requires administrative access to the system.
- Abuse of the "Add data source" feature.
- Risk of unauthorized operating system commands.
Live Threat
Current exploitation, exposure, and threat context
An attacker with administrative rights on Percona Monitoring and Management (PMM) could execute arbitrary shell commands on the underlying operating system. This is possible by abusing the "Add data source" feature, which allows an internal database user with superuser privileges to break out of the database context.
- Underlying operating system.
- Abuse of "Add data source" feature.
- Arbitrary shell command execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
The discovery of an internal database user retaining superuser privileges in Percona Monitoring and Management (PMM) necessitates action from infrastructure and platform teams. Attackers with `pmm-admin` rights can exploit the "Add data source" feature to execute shell commands on the operating system. The first practical step is to identify all PMM instances, confirm their reachability and criticality, and then ascertain the accountable owner to plan remediation based on assessed risk.
- Platform and infrastructure teams own.
- Verify PMM instance reachability and criticality.
- Plan remediation based on assessed risk.