Описание
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An attacker can exploit DNS rebinding to exfiltrate the full system monitoring dataset from a victim's browser. This vulnerability is fixed in 4.5.5.
A vulnerability in the Glances XML-RPC server fails to properly validate HTTP Host headers, enabling DNS rebinding attacks. If a user is tricked into visiting a malicious website, a remote attacker can exploit this flaw to exfiltrate sensitive system monitoring data.
Отчет
This moderate DNS rebinding vulnerability in the Glances XML-RPC server allows for information disclosure. An attacker can exfiltrate system monitoring data, provided they trick a user into visiting a malicious site.
Меры по смягчению последствий
The XML-RPC server is a legacy interface started via the -s or --server flags. To maintain remote monitoring functionality securely, operators should migrate to the actively maintained REST API by starting Glances with the -w or --webserver flag instead. The REST API component is protected against DNS rebinding attacks.
Дополнительная информация
Статус:
EPSS
5.3 Medium
CVSS3
Связанные уязвимости
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An attacker can exploit DNS rebinding to exfiltrate the full system monitoring dataset from a victim's browser. This vulnerability is fixed in 4.5.5.
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leaving it vulnerable to DNS rebinding attacks. An attacker can exploit DNS rebinding to exfiltrate the full system monitoring dataset from a victim's browser. This vulnerability is fixed in 4.5.5.
Glances is an open-source system cross-platform monitoring tool. Prior ...
Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding Attack
EPSS
5.3 Medium
CVSS3