T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/pan.py:3633- Finding
Unauthenticated Download and Task-Control API Allows Remote Operations
- Content
View full analysis
Vulnerability Details
File Location:
scripts/pan.py, lines 3108-3190 and 3633-3717
Vulnerability Type: Missing authentication and authorization on state-changing HTTP endpoints
Risk Level: HighVulnerable Code
python def _apply_task_action(reports_dir, task_id, action): """Apply pause/resume/delete/retry to a task control record.""" path, rec = _locate_task_control(reports_dir, task_id) if not path or not rec: return False, "Task %s not found" % task_id recs = read_task_records(path) now = datetime.now().strftime("%Y-%m-%dT%H:%M:%S%z") if action == "pause": if rec.get("state") != "running": return False, "Only running tasks can be paused" rec["state"] = "paused" elif action == "resume": if rec.get("state") != "paused": return False, "Only paused tasks can be resumed" rec["state"] = "running" elif action == "delete": if rec.get("state") == "running": rec["state"] = "cancelled" rec["updated"] = now rec["finished"] = rec.get("finished") or now _atomic_write_json(path, {"schema": 1, "tasks": recs}) return True, "Cancellation and deletion marker sent" recs.pop(task_id, None) _atomic_write_json(path, {"schema": 1, "tasks": recs}) return True, "Task record deleted" elif action == "retry": if rec.get("state") not in ("done", "failed", "cancelled"): return False, "Only completed tasks can be retried" pid, err = _spawn_retry_task(rec) if err: return False, errpython def _spawn_download_task(url, pwd="", to="", engine="", tier="", path=""): """Start pan get --live in the background.""" if not url or not url.strip(): return "", "url is empty" argv = [sys.executable, str(Path(__file__).resolve()), ...[truncated 5441 chars]- Remediation
View remediation
Remediation Suggestions
- Require authentication for all API endpoints, using an unguessable bearer token, mutually authenticated TLS, or an authenticated reverse proxy.
- Refuse non-loopback binding unless authentication is explicitly configured and validated.
- Apply authorization per task so callers can only view or modify tasks they created.
- Remove task mutations from GET routes and require authenticated POST requests with CSRF protection.
- Restrict
todestinations to canonical paths beneath one or more configured download roots. Resolve symbolic links and reject paths that escape those roots. - Apply allowlists to selectable engines, tiers, and remote paths.
- Add request-body size limits, rate limits, concurrent-job limits, and storage quotas.
- Avoid exposing sensitive report fields and local filesystem paths to unauthenticated clients.
- Bind remote deployments to
127.0.0.1by default and require access through an authenticated SSH tunnel or secured reverse proxy.
