T05 · Unauthorized Access and Privilege Escalation
- Location
references/domain-guides/compute-container-network/scripts/collect_clb_backend_context.py:151- Finding
ALB Collector Enumerates Unrelated VPC Server Groups and Backend Infrastructure
- Content
View full analysis
Vulnerability Details
File Location:
references/domain-guides/compute-container-network/scripts/collect_clb_backend_context.py, lines 151-196 and 211-231
Vulnerability Type: Least-privilege violation through overbroad cloud-resource enumeration
Risk Level: MediumVulnerable Code
python lbs = list_from(lb_resp, "load_balancers", "LoadBalancers") vpc_id = (lbs[0].get("vpc_id") or lbs[0].get("VpcId")) if lbs else None listeners_resp = to_dict( alb.describe_listeners( volcenginesdkalb.DescribeListenersRequest( load_balancer_id=load_balancer_id, listener_ids=[listener_id] if listener_id else None, page_size=100, ) ) ) server_groups_resp = to_dict( alb.describe_server_groups( volcenginesdkalb.DescribeServerGroupsRequest( vpc_id=vpc_id, page_size=100, ) ) ) listeners = list_from(listeners_resp, "listeners", "Listeners") server_groups = list_from(server_groups_resp, "server_groups", "ServerGroups") listener_ids = sorted( collect_values(listeners, ["listener_id", "ListenerId"]) ) server_group_ids = sorted( collect_values(server_groups, ["server_group_id", "ServerGroupId"]) | collect_values(listeners, ["server_group_id", "ServerGroupId"]) ) health = [] for lid in listener_ids: health.append( to_dict( alb.describe_listener_health( volcenginesdkalb.DescribeListenerHealthRequest( listener_ids=[lid], only_un_healthy=False, ) ) ) ) attrs = [] for sgid in server_group_ids: attrs.append( to_dict( alb.describe_server_group_attributes( volcenginesdkalb.DescribeServerGroupAttributesRequest( server_group_id=sgid ) ) ) ) backend_instance_ids = sorted( collect_values(attrs, ["instance_id", "InstanceId"]) ) return { ...[truncated 3637 chars]- Remediation
View remediation
Remediation Suggestions
- Derive server-group IDs only from listeners or forwarding rules associated with the requested ALB.
- If the SDK supports a load-balancer-specific filter for
DescribeServerGroups, pass the requested load balancer ID rather than querying solely by VPC ID. - Remove the union between listener-associated server groups and every group returned by the VPC-wide query.
- Before retrieving server-group attributes, verify that each group is explicitly linked to the requested ALB.
- Make complete raw responses opt-in. Return a minimal, redacted summary by default.
- Avoid returning unrelated ECS metadata and limit selected fields to those needed for backend-health diagnosis.
- Add an explicit maximum number of groups and backend instances that may be inspected.
- Add regression tests with at least two ALBs in the same VPC and verify that a query for one ALB never returns the other ALB's server groups or backend instances.
- Update the script documentation to describe the exact query scope and any optional raw-output behavior.
