oss-sec mailing list archives
Re: [Nagios-devel] [oss-security] Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view)
From: Andreas Ericsson <ae () op5 se>
Date: Wed, 04 Sep 2013 12:54:00 +0200
On 2013-09-04 11:37, Jochen Bern wrote:
On 04.09.2013 11:03, Andreas Ericsson wrote:On 2013-09-04 10:31, Jonas Meurer wrote:The indisputable part of this change is, that users are allowed to see hostgroups and servicegroups with at least one authorized host or service. Unclear is, whether this means "group and all its group members", or "group and only authorized group members".It should mean "group and only authorized group members, except also hosts for services where one is authorized to see the service".[...]Well, it *was* by design, but now I'm changing the design. It's a good time for it, since 4.0 is about to come out. I think the security teams can move on and we'll consider this "changed" rather than "fixed" for 4.0, where we do some security tightening.Since you do seem to be willing to ponder the system of access rights and its security implications: I haven't checked the 4.x prereleases yet, does being authorized to see a host's information still necessarily provide access to *all* services on it?
AFAIK, yes. Please understand that I'm very uninterested in changes to the UI though, and I'd be much (much) happier if UI and core were split into two different components.
In the "customers accessing provider's Nagios" scenario, I suppose that the customer might be interested in seeing "application is running" but not, say, "the snmpd that ties this machine to the provider's NMS is acting up" ...
I agree. The problem is that with access to the host comes access to commands that affect all services on that host as well, so it's not necessarily as clearcut as "disable viewing here and we're done", if one wants to do things properly. -- Andreas Ericsson andreas.ericsson () op5 se OP5 AB www.op5.se Tel: +46 8-230225 Fax: +46 8-230231 Considering the successes of the wars on alcohol, poverty, drugs and terror, I think we should give some serious thought to declaring war on peace.
Current thread:
- Re: CVE request: unauthorized host/service views displayed in servicegroup view, (continued)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Jonas Meurer (Jul 10)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Vincent Danen (Aug 02)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Kurt Seifried (Aug 02)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Jonas Meurer (Aug 03)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Jonas Meurer (Aug 30)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Kurt Seifried (Sep 03)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Vincent Danen (Sep 03)
- Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Jonas Meurer (Sep 04)
- Re: Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Andreas Ericsson (Sep 04)
- Re: [Nagios-devel] [oss-security] Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Jochen Bern (Sep 04)
- Re: [Nagios-devel] [oss-security] Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Andreas Ericsson (Sep 04)
- Re: Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Jonas Meurer (Sep 04)
- Re: Security bug or feature? Servicegroups leak hostnames to unauthorized users (Was: [oss-security] CVE request: unauthorized host/service views displayed in servicegroup view) Jonas Meurer (Sep 04)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Vincent Danen (Aug 02)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Jonas Meurer (Jul 10)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Daniel Kahn Gillmor (Sep 04)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Vincent Danen (Sep 04)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view cve-assign (Sep 04)
- Re: CVE request: unauthorized host/service views displayed in servicegroup view Vincent Danen (Sep 04)
- Re: Re: CVE request: unauthorized host/service views displayed in servicegroup view Kurt Seifried (Sep 04)