Horizon Alert
Summary of the vulnerability and why it matters
This advisory highlights a critical vulnerability in Homer, an open-source observability software used in telecommunications. The issue allows for unauthenticated access to protected API endpoints on default installations, potentially exposing sensitive operational data. Confirmation of relevance and exposure is the primary concern.
- Unauthenticated access to telecom data APIs.
- Critical for securing operational data visibility.
- Confirm relevance and exposure; protect sensitive data.
Attack Path
How an attacker could exploit the issue
Attackers can access unauthenticated API endpoints by exploiting a default configuration in the Homer JWT middleware. Since the JWT secret defaults to an empty string, all protected API endpoints under `/api/v1`, `/api/v3`, and `/api/v4` are left open to unauthenticated access. This could allow an attacker to compromise the confidentiality, integrity, and availability of the observability data.
- Unauthenticated network access required.
- Default empty JWT secret triggers vulnerability.
- Complete data compromise is possible.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, unauthenticated access to protected API endpoints in Homer could allow unauthorized users to view, modify, or delete system data. This occurs because the JWT middleware functions do not properly validate tokens when the JWT secret is an empty string, which is the default configuration.
- Unauthenticated API access.
- Default configuration allows bypass.
- Unauthorized data access and modification.
Operational Fix
Recommended remediation, mitigation, and detection steps
The Homer observability software's default JWT secret can lead to unauthenticated access to critical API endpoints. Infrastructure and platform teams are likely responsible for managing Homer deployments. The immediate first step is to identify all Homer instances, verify their accessibility and business criticality, and then confirm the accountable owner for remediation planning.
- Determine Homer instance ownership.
- Verify API endpoint exposure and criticality.
- Plan remediation based on assessed risk.