Database/Control plane, storage & DevOps
Linuxfabrik monitoring plugins: sudo-authorized checks read arbitrary root-readable files via --test
Impact
lib.lftest.test() treated an element of the --test CSV argument as a filesystem path and returned the file's contents as simulated plugin output, with no path confinement. The --test argument is hidden but accepted in production, and these checks are normally invoked through sudo from the monitoring account, so an attacker holding the nagios or icinga user reads any root-readable file on the host. deb-updates with its default QUERY=1 discloses a file line by line; roughly 22 other plugins leak filtered content or act as a root-file existence and readability oracle, and network-bonding and openstack-swift-stat had direct read paths of their own. Monitoring agents are installed identically on every node, so one compromised monitoring account scales to fleet-wide disclosure of kubeconfigs, BMC and Redfish credentials, and private keys.
Who can reach it
Local attacker who controls the nagios or icinga service account on a monitored host, using the sudo rules those plugins are normally authorized under. No further authentication needed.
What to do
Upgrade linuxfabrik-lib to 6.1.0 and Linuxfabrik Monitoring Plugins to 7.0.0 — the library fix confines fixture reads to the invoking plugin's unit-test directory and refuses unsafe anchors, and the plugin fix routes the two direct-read bypasses through that helper. Package update on every monitored host plus a monitoring agent restart; no reboot. Also review the sudo rules granted to the monitoring account while you are there.
References
Related entries
- community.general ipa_getkeytab: IPA/LDAP bind password written to logs and exposed in the process listCVE-2026-80158 · Ansible community.general ipa_getkeytab module (bind_pw not declared no_log)Medium
- Harbor (audit log redaction, LDAP password and OIDC client secret): CREDENTIAL DISCLOSURE VIA THE AUDIT TRAIL: HarborNCVD-2026-058-harbor-audit-log-redaction-ldap · Harbor (audit log redaction, LDAP password and OIDC client secret)Medium
- Kubeflow (central dashboard, reflected cross-site scripting): Reflected XSS in the Kubeflow dashboard runs attackerCVE-2023-6571 · Kubeflow (central dashboard, reflected cross-site scripting)Medium
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsCVE-2026-12910 · GitLab CE/EE (SAML SSO sign-in enforcement)Medium
- Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by adminsCVE-2026-13720 · Grafana dashboard API (grafana.app/managedBy provisioning annotations)Medium
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessCVE-2026-4398 · GitLab EE self-managed (compliance framework namespace validation)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.