GHSA-2q4p-f6gf-mqr5
Graylog server has partial path traversal vulnerability in Support Bundle feature
Quick fix
GHSA-2q4p-f6gf-mqr5 — org.graylog2:graylog2-server: upgrade to the fixed version with the command below.
# pom.xml: bump <version>5.1.3</version> for org.graylog2:graylog2-serverDetails
A partial path traversal vulnerability exists in Graylog's [Support Bundle](https://go2docs.graylog.org/5-1/making_sense_of_your_log_data/cluster_support_bundle.htm) feature. The vulnerability is caused by incorrect user input validation in an HTTP API resource.
Thanks to weiweiwei9811 for reporting this vulnerability and providing detailed information.
### Impact
Graylog's Support Bundle feature allows an attacker with valid Admin role credentials to download or delete files in sibling directories of the support bundle directory.
The default `data_dir` in operating system packages (DEB, RPM) is set to `/var/lib/graylog-server`. The data directory for the Support Bundle feature is always `<data_dir>/support-bundle`.
Due to the partial path traversal vulnerability, an attacker with valid Admin role credentials can read or delete files in directories that start with a `/var/lib/graylog-server/support-bundle` directory name.
The vulnerability would allow the download or deletion of files in the following example directories.
- `/var/lib/graylog-server/support-bundle-test` - `/var/lib/graylog-server/support-bundlesdirectory`
For the [Graylog](https://hub.docker.com/r/graylog/graylog) and [Graylog Enterprise](https://hub.docker.com/r/graylog/graylog-enterprise) Docker images, the `data_dir` is set to `/usr/share/graylog/data` by default.
### Patches
The vulnerability is fixed in Graylog version 5.1.3 and later.
### Workarounds
Block all HTTP requests to the following HTTP API endpoints by using a reverse proxy server in front of Graylog.
- `GET /api/system/debug/support/bundle/download/{filename}` - `DELETE /api/system/debug/support/bundle/{filename}`
Are you affected?
Enter the version of the package you're using.
Affected packages
5.1.0Fixed in: 5.1.3# pom.xml: bump <version>5.1.3</version> for org.graylog2:graylog2-serverReferences
- https://github.com/Graylog2/graylog2-server/security/advisories/GHSA-2q4p-f6gf-mqr5[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-41044[ADVISORY]
- https://github.com/Graylog2/graylog2-server/commit/02b8792e6f4b829f0c1d87fcbf2d58b73458b938[WEB]
- https://github.com/Graylog2/graylog2-server[PACKAGE]
- https://go2docs.graylog.org/5-1/making_sense_of_your_log_data/cluster_support_bundle.htm[WEB]