T09 · Insecure Skill Coding Practices
- Location
server.js:89- Finding
Unauthenticated Status API Exposes Sensitive Operational Data
- Content
View full analysis
{ // CORS res.setHeader("Access-Control-Allow-Origin", "*"); res.setHeader("Access-Control-Allow-Methods", "GET, OPTIONS"); res.setHeader("Access-Control-Allow-Headers", "Content-Type"); if (req.method === "OPTIONS") { res.writeHead(204); res.end(); return; } if (req.url === "/status" || req.url === "/") { if (cachedStatus) { res.writeHead(200, { "Content-Type": "application/json", "Cache-Control": `public, max-age=${Math.ceil(CACHE_TTL / 1000)}`, }); res.end(JSON.stringify(cachedStatus)); } else { res.writeHead(503, { "Content-Type": "application/json" }); res.end(JSON.stringify({ error: "starting up, no data yet" })); } } else if (req.url === "/health") { res.writeHead(200, { "Content-Type": "application/json" }); res.end(JSON.stringify({ status: "ok", uptime: formatUptime(Date.now() - startTime) })); } else { res.writeHead(404); res.end("Not Found"); } }); server.listen(PORT, "0.0.0.0", () => { console.log(`[bot-status] ${config.name} Status API`); console.log(`[bot-status] Listening on http://0.0.0.0:${PORT}`); }); ``` ### Technical Analysis The service binds to `0.0.0.0`, exposes `/status` without authentication or authorization, and permits browser access from every origin through `Access-Control-Allow-Origin: *`. It also marks the sensitive response as publicly cacheable. The response aggregates data from all collectors, including: - Hostname, configured IP address, CPU, memory, and dis ...[truncated 1735 chars]- Remediation
View remediation
