Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability in GravitLauncher's file server allows unauthenticated remote attackers to read sensitive files, potentially exposing signing keys, authentication tokens, and credentials. This could enable forged administrative access and complete bypass of authentication mechanisms, impacting the security of services that rely on this launcher.
- Unauthenticated attackers can access sensitive files remotely.
- Compromised credentials could allow forged administrative access.
- Confirm relevance and exposure of this launcher's services.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can send specially crafted HTTP requests to the GravitLauncher's file server. The server mishandles requests that lack a leading slash, allowing the attacker to read sensitive files from the server's file system. This could expose private keys, authentication tokens, or database credentials, potentially leading to forged administrative access and complete authentication bypass.
- No authentication required.
- Triggered by unnormalized file path requests.
- Risk of credential exposure and auth bypass.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated remote actor could read sensitive files from the GravitLauncher server when a specific file server is enabled and accessible. This could expose signing keys, refresh tokens, and database credentials.
- Sensitive file access.
- Unauthenticated HTTP requests.
- Forged administrative access tokens.
Operational Fix
Recommended remediation, mitigation, and detection steps
The GravitLauncher's file server is likely managed by the application or platform team responsible for its deployment and operation. The first practical step is to identify all instances of the GravitLauncher, confirm if the file server on port 9274 is exposed externally and accessible, and determine if it is business-critical. Once identified and assessed, an accountable owner should be assigned to plan remediation, prioritizing instances with the highest risk.
- Application or platform teams own the issue.
- Verify external exposure and reachability first.
- Plan remediation based on identified risk.