Skip to content

Agent fallbacks on "rudder" host when no policy server is configured

Low
amousset published GHSA-8c49-vg95-2c84 Jul 11, 2023

Package

rudder-agent (rudder)

Affected versions

< 7.3.0

Patched versions

7.3.0

Description

Impact

When installing a Rudder agent, if no policy server is configured, the agent would fallback to sending an inventory to the rudder host in the network (if it resolves). This was meant to make installation more convenient, but could be a security issue if policy servers are not immediately configured and the domain is not controlled (or in case of an attack on DNS). As this feature was not broadly used, it was removed in 7.3.

Patches

This behavior has been removed in 7.3 on 2023/04/07.

Workarounds

Define the policy server during agent provisioning.

References

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs