T09 · Insecure Skill Coding Practices
- Location
SKILL.md:349- Finding
Path Traversal Through Unvalidated Job Name in Logging Wrapper
- Content
View full analysis
[args...]}" shift COMMAND=("$@") LOG_DIR="/var/log/cron-jobs" mkdir -p "$LOG_DIR" LOG_FILE="$LOG_DIR/$JOB_NAME.log" ``` ### Technical Analysis The wrapper accepts `JOB_NAME` from its first command-line argument and directly incorporates it into `LOG_FILE`. Although the variable is quoted during subsequent use, quoting only prevents shell word splitting and command substitution; it does not prevent filesystem path traversal. A job name containing directory separators or traversal components, such as `../../target`, can cause the resolved log path to escape `/var/log/cron-jobs`. The `.log` suffix limits the set of directly addressable names but does not prevent writes outside the intended directory. Existing symbolic links can further increase the reachable scope. This example is particularly sensitive because cron wrappers commonly run under service accounts or `root`, and the document places logs under `/var/log`, which usually requires elevated privileges. ### Attack Path 1. An attacker gains the ability to configure a scheduled invocation or otherwise control the wrapper's first argument. 2. The attacker supplies a crafted job name containing path traversal components, such as `../../some-directory/target`. 3. The wrapper constructs a path resembling: ```text /var/log/cron-jobs/../../some-directory/target.log ``` 4. The operating system resolves the traversal components outside the intended logging directory. 5. When the wrapper appends status messages or command output, data is written using the wrapper's privileges. 6. If the destination is an existing file or a usable symbolic link, the attacker may corrupt or modify a file accessible to the scheduled job. ### Impact Assessment ...[truncated 661 chars]- Remediation
View remediation
&2 exit 2 } ``` 2. Explicitly reject `/`, `\`, `..`, control characters, and empty values. 3. Canonicalize the resulting path and verify that it remains beneath the canonical `LOG_DIR`. 4. Create the log directory with restrictive ownership and permissions: ```bash install -d -m 0750 -o root -g cron-jobs /var/log/cron-jobs ``` 5. Prevent symbolic-link following when opening log files, using a small helper that supports `O_NOFOLLOW` where shell facilities are insufficient. 6. Run each scheduled task under the least-privileged dedicated service account rather than `root`. 7. Ensure only trusted administrators can configure the wrapper's arguments or modify the relevant crontab or timer unit. ]]>
