Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects the Crawlab platform, specifically how it handles security tokens. The system uses a fixed, hard-coded secret to sign important tokens, which an attacker could exploit to impersonate administrators. This could allow them to gain unauthorized access to administrative functions and potentially run malicious code on connected systems.
- Unprotected secret allows unauthorized admin access.
- Hard-coded secret is a critical, long-term risk.
- Confirm if this platform is in use.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit a hard-coded secret used for signing security tokens. This allows them to create their own tokens, granting them administrative access to the system. Once authenticated as an administrator, they can potentially execute code on connected worker nodes.
- Network access and no authentication needed.
- Forging administrator tokens.
- Execute code on worker nodes.
Live Threat
Current exploitation, exposure, and threat context
An unauthenticated attacker could forge administrator tokens to access administrative APIs and execute code on worker nodes. This is possible due to a hard-coded secret used for signing JWT tokens, which cannot be changed through configuration or environment variables. The vulnerability affects Crawlab through version 0.6.3.
- Administrator API access and code execution.
- Forging JWT tokens using a hard-coded secret.
- Compromised worker nodes and system control.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in Crawlab allows unauthenticated attackers to forge administrative tokens, potentially leading to code execution on worker nodes. The primary responsibility for managing and securing Crawlab likely falls on platform or infrastructure teams, in coordination with application owners if Crawlab is integrated into specific workflows. The first step should be to identify all Crawlab instances, determine their reachability and business criticality, and then assign ownership for remediation planning.
- Platform/Infrastructure teams own remediation.
- Verify Crawlab reachability and criticality.
- Plan remediation based on identified risk.