will-moss Isaiah
- <= 1.36.9
A vulnerability exists in will-moss Isaiah versions through 1.36.9, specifically within the Websocket Connection Authentication component. The issue arises in an unknown function of the file app/main.go, where improper authentication is introduced. This vulnerability can be exploited remotely, allowing unauthorized access to authenticated application functions. As a result, it may expose sensitive Docker information and management capabilities, potentially leading to a significant administrative compromise.
Exploitation of this vulnerability allows an unauthenticated network client to access normal authenticated functions within the Isaiah application. Given that Isaiah manages Docker resources, this could result in unauthorized exposure of container metadata, logs, environment variables, and Docker management operations. Depending on the deployment and access to the Docker daemon, such exploitation could culminate in a high-impact administrative compromise.
The vulnerability can be reproduced by enabling Forward Proxy Authentication in the Isaiah application while the backend is accessible by an untrusted client. During the Websocket handshake, the client can supply a header that bypasses the standard authentication process, gaining unauthorized access to the application.
Users are advised to ensure that the Isaiah backend is not directly reachable by untrusted clients, and to configure their proxy to overwrite or strip user-supplied authentication headers. Additionally, the application should be updated to a version where this vulnerability is addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.