Limit body size for all requests
Maintainer thường phản hồi trong vòng 1 ngày
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức phù hợp với người mới
- 50/100
Hướng nghiên cứu
Bắt đầu với UpdateConfig trong api/plugin.go và lần theo việc xử lý request qua router/router.go; đồng thời xem xét api/user.go, auth/authentication.go và plugin/manager.go để kiểm tra các đường dẫn truy cập bị ảnh hưởng. Chạy các bài kiểm thử server liên quan và coi công việc là hoàn tất khi các request, bao gồm /message và /plugin/{id}/config, áp dụng giới hạn body mặc định có thể cấu hình mà không từ chối các payload hợp lệ.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
We should limit the body size for all requests. It's currently possible to send big messages to /message or big yaml configs to /plugin/{id}/config.
I guess a good default could be something like 10MB, but it should be configurable.
Email Report
Summary
Gotify Server's plugin configuration update feature accepts
attacker-controlled YAML bodies at POST /plugin/{id}/config.
Confirmed in v2.9.1, when registration=true and at least one
installed plugin supports Configurer, an unauthenticated remote
attacker can self-register and submit an oversized configuration body to
trigger severe memory pressure and persistent configuration storage
growth.
Details
UpdateConfig verifies plugin ownership and Configurer support, but
then immediately calls io.ReadAll(ctx.Request.Body) with no size
limit. The full request body is buffered before YAML parsing or
plugin-side validation, so any reachable caller can force memory
allocation proportional to the submitted body size. After validation,
the handler stores the original bytes in conf.Config, which turns the
same endpoint into a persistence amplifier rather than only a transient
parse-time sink.
conf, err := c.DB.GetPluginConfByID(id)
...
if aborted := supportOrAbort(ctx, instance, compat.Configurer); aborted { return }
newconfBytes, err := io.ReadAll(ctx.Request.Body)
...
if err := yaml.Unmarshal(newconfBytes, newConf); err != nil { ... }
if err := instance.ValidateAndSetConfig(newConf); err != nil { ... }
conf.Config = newconfBytes
When registration=true, POST /user is reachable under
authentication.Optional() and allows unauthenticated non-admin
account creation. User creation triggers fireUserAdded, which
initializes per-user instances for all installed plugins, and
RequireClient accepts Basic Auth directly. The attacker can then call
GET /plugin to enumerate a plugin instance whose capabilities
include configurer, fetch the current YAML from
GET /plugin/{id}/config, and reuse that id against
POST /plugin/{id}/config.
Because the handler stores raw YAML bytes rather than a normalized
representation, the attacker can append large YAML comment blocks to an
otherwise valid configuration. yaml.Unmarshal ignores comments, but
the oversized original document is still persisted as
PluginConf.Config. I verified the unbounded body read and raw-byte
persistence in api/plugin.go, and the self-registration plus Basic
Auth reachability in api/user.go, router/router.go,
auth/authentication.go, and plugin/manager.go. I did not identify
a fixed version from the current materials.
PoC
-
Ensure the target runs Gotify Server
v2.9.1with
registration=trueand at least one installed plugin whose
/pluginentry listsconfigurerincapabilities. -
Create a normal account:
POST /user
Content-Type: application/json
{"name":"pocuser","pass":"PocPassw0rd!"}
-
Use Basic Auth for that account to call
GET /plugin, select an
entry whosecapabilitiesarray containsconfigurer, then fetch
its current YAML fromGET /plugin/{id}/config. -
Append a large number of YAML comment lines to the returned document
and submit it back:
POST /plugin/{id}/config
Authorization: Basic <base64(pocuser:PocPassw0rd!)>
Content-Type: application/x-yaml
<original valid YAML>
# padding 000001
# padding 000002
...
- Observe high memory pressure during the request. If the YAML remains
otherwise valid, a subsequentGET /plugin/{id}/configreturns the
enlarged document, confirming that the oversized raw body was
persisted.
Impact
Observed impact is a conditional unauthenticated network denial of
service in deployments that allow self-registration and have at least
one installed Configurer plugin: a remote attacker can consume
process memory with a single oversized request and can repeatedly
enlarge persisted plugin configuration data. Where registration is
disabled, the same bug remains reachable to a low-privilege
authenticated user. I did not confirm confidentiality or integrity
impact from current evidence.
- Ngôn ngữ chính
- Go
- Star
- 16k
- Fork
- 887
- Merge trung bình
- 1 ngày 6 giờ
- Pull request đã merge (30 ngày)
- 5
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của gotify/server
-
a:bug
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 48/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 68/100
gotify/server#1059 · 3 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
a:bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
gotify/server#1055 · 7 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Session elevation duration is unbounded, and large values silently overflow to a past timestampĐang mởa:bug
Độ khó 3/5 1-2 ngày Mức phù hợp với người mới 78/100
gotify/server#1051 · 2 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
a:bug
Độ khó 4/5 3-5 ngày Mức phù hợp với người mới 48/100
gotify/server#1047 · 6 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
Tất cả issue của gotify/server
Issue tương tự
-
flaky-test
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 1/5 Dưới một giờ Mức phù hợp với người mới 88/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
Maintainer thường phản hồi trong vòng 2 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 72/100
SocialGouv/iterion#2108 ·
Maintainer thường phản hồi trong vòng 1 ngày