T09 · Insecure Skill Coding Practices
- Location
SKILL.md:234- Finding
Loki Authentication Disabled in Deployment Template
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md:234
Vulnerability Type: Unauthenticated access to log aggregation services
Risk Level: Mediumyaml # loki-config.yml auth_enabled: false server: http_listen_port: 3100Technical Analysis
The Loki configuration explicitly sets
auth_enabled: false, placing the service in unauthenticated, single-tenant mode. The template does not prescribe an authenticated reverse proxy, network access controls, TLS, or another compensating security boundary.If port
3100is exposed to an untrusted network, any client able to connect to the Loki API may submit queries without presenting credentials. Depending on the enabled Loki APIs and surrounding deployment controls, an unauthorized client may also submit forged log entries. This is a configuration vulnerability rather than evidence of intentionally malicious behavior.Attack Path
- A user deploys Loki using the supplied configuration.
- Loki listens on port
3100, and that port becomes reachable from an untrusted network through a container mapping, firewall rule, ingress, or load balancer. - An attacker discovers the endpoint through network scanning or service enumeration.
- The attacker accesses unauthenticated Loki endpoints to enumerate labels, streams, and stored log data.
- The attacker queries logs for operational details or sensitive values such as internal hostnames, user identifiers, request data, tokens, or credentials accidentally recorded by applications.
- Where log-ingestion endpoints are also exposed, the attacker may submit fabricated entries, degrading monitoring integrity or triggering misleading investigations and alerts.
Impact Assessment
Exploitation does not directly grant operating-system privileges. It can, however, expose all log streams available in the unauthenticated Loki tenant and disclose sensitive operational or application data. Information recovered ...[truncated 415 chars]
- Remediation
View remediation
Remediation Suggestions
- Do not expose Loki port
3100directly to public or otherwise untrusted networks. - Place Loki behind an authenticated reverse proxy or observability gateway that enforces identity and authorization for both query and ingestion APIs.
- Restrict access using firewall rules, private networking, Kubernetes NetworkPolicies, or equivalent controls.
- Enable TLS at the gateway and use encrypted service-to-service transport where appropriate.
- Separate read and write access, granting clients only the minimum APIs required for their roles.
- Add rate limits and request-size controls to reduce log-injection and resource-exhaustion risks.
- Document this unauthenticated configuration as suitable only for isolated local development, and provide a hardened production example with explicit compensating controls.
- Prevent applications from logging credentials, tokens, and other secrets; apply redaction and retention controls to limit the impact of log exposure.
- Do not expose Loki port
