VDB
Sign up
LOW3.7

GHSA-g8rh-fjm6-h2h9

LF Edge eKuiper: Self-XSS in External Service Creation

Quick fix

GHSA-g8rh-fjm6-h2h9 — github.com/lf-edge/ekuiper/v2: upgrade to the fixed version with the command below.

go get github.com/lf-edge/ekuiper/v2@v2.4.0

Details

### Summary A Cross-Site Scripting (XSS) vulnerability in external service creation allows an authenticated attacker to inject HTML/script payloads into external service names, which may execute in a user's browser when rendered by administrative web interfaces.

### Details Prior to v2.4.0, external service registration endpoints did not strictly enforce alphanumeric character restrictions on service names. An operator or attacker with API access could register a service using a crafted name containing HTML elements (such as `<iframe src="...">`). If an administrative web UI rendered the unescaped service name, arbitrary script execution could occur in the context of the user's browser session.

### PoC 1. Create an external service JSON definition with a filename containing an XSS payload, e.g. `<iframe src="javascript:alert`1337`">.json` inside a ZIP archive. 2. In external service creation, upload the ZIP and provide the matching service name: `<iframe src="javascript:alert`1337`">`. 3. Upon service registration, the unescaped name executes when rendered in the UI context.

### Impact Self-XSS / Stored XSS leading to potential session token leakage or unauthorized actions in the context of the affected user's browser session.

### Remediation & Patches - **Upgrade to eKuiper >= 2.4.0**: Strict alphanumeric identifier validation (`validate.ValidateID`) is now enforced on all external service creation and update endpoints, rejecting invalid characters.

### Workarounds - Protect eKuiper management endpoints (`POST /services`) with authentication and network-level firewalls.

### Credits - Reported by Alexey Kosmachev, Bi.Zone (@TheMostKnown)

Are you affected?

Enter the version of the package you're using.

Affected packages

Go/github.com/lf-edge/ekuiper/v2
Introduced in: 0Fixed in: 2.4.0
Fixgo get github.com/lf-edge/ekuiper/v2@v2.4.0

References