SigNoz 0.88.0 through 0.141.0 - Missing Authentication on Trace Funnel Analytics Endpoints
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
SigNoz versions 0.88.0 through 0.141.0 fail to apply authorization wrappers to trace-funnel analytics endpoints in the HTTP handler. Unauthenticated attackers can submit arbitrary funnel definitions to retrieve trace analytics including identifiers, durations, span counts, service topology, and error activity without credentials.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
SigNoz · signozReferences
https://github.com/SigNoz/signozhttps://github.com/SigNoz/signoz/blob/v0.141.0/pkg/query-service/app/http_handler.go#L4073-L4086https://github.com/SigNoz/signoz/commit/f78bd492d8732f011bc96837cf9862db2df0783dhttps://github.com/SigNoz/signoz/pull/12817https://github.com/SigNoz/signoz/releases/tag/v0.141.1https://github.com/SigNoz/signoz/security/advisories/GHSA-v549-7j2x-qjm5https://www.vulncheck.com/advisories/signoz-0.88.0-through-0.141.0-missing-authentication-on-trace-funnel-analytics-endpoints