Horizon Alert
Summary of the vulnerability and why it matters
This advisory details a critical vulnerability in OpenStack Zaqar's WSGI transport that could allow unauthenticated attackers to bypass authentication and access project resources. If administrative roles are claimed, these attackers could also perform administrative actions. The vulnerability is present in deployments using the WSGI transport with authentication.
- Unauthenticated access to project queues and messages.
- Affects systems using WSGI transport with authentication.
- Confirm relevance and exposure to Zaqar WSGI deployments.
Attack Path
How an attacker could exploit the issue
An attacker can bypass authentication and pre-signed URL verification by sending a request with an empty URL-Signature header to the WSGI transport of OpenStack Zaqar. This allows them to manipulate queues, messages, claims, and subscriptions within a known project, and potentially perform administrative actions if they can also claim an administrative role.
- Requires network access and knowledge of a project's UUID.
- Triggers when an empty URL-Signature header is sent.
- Risk includes unauthorized data access and administrative control.
Live Threat
Current exploitation, exposure, and threat context
In OpenStack Zaqar deployments using the WSGI transport with authentication, an unauthenticated attacker could bypass security controls to access project-specific queues, messages, claims, and subscriptions. This could potentially extend to administrative operations in certain configurations.
- Project data and queues at risk.
- Bypasses authentication via crafted header.
- Allows unauthorized data access and modification.
Operational Fix
Recommended remediation, mitigation, and detection steps
For deployments utilizing OpenStack Zaqar with the WSGI transport, the platform or infrastructure teams are typically responsible for its management and security. The first practical step is to identify all instances of Zaqar using WSGI transport, confirm their reachability and business criticality, and then identify the accountable project owner to plan remediation based on the assessed risk.
- Platform/Infrastructure teams own the issue.
- Verify WSGI transport and project UUID knowledge.
- Plan remediation based on identified risk.