Synopsis
In Hermes Agent the public POST /auth/password-login route copies the client-supplied provider value, with no size limit, into the audit log before rejecting an unknown provider.
Because the middleware treats this route as public, an unauthenticated client with no account can cause arbitrarily large, attacker-controlled data to be written persistently to the server's disk.
In hermes_cli/dashboard_auth/routes.py, _PasswordLoginBody.provider is declared as a str with no maximum length. The auth_password_login handler applies the attempt limit, fails to find the provider, and then passes body.provider to audit_log before returning 404.
In hermes_cli/dashboard_auth/audit.py, the logger filters certain sensitive field names but never bounds value size. It serializes the full object as JSON and appends it to dashboard-auth.log.
Testing confirmed the behavior. A request with a nonexistent provider and empty credentials returned the expected 404. Raising provider to about 4.19 million characters still returned 404, but the free disk space reported by /api/status dropped from 923 MB to 919 MB, and the value stayed in the log after the request ended.
A single request with a total JSON size of exactly 100 MiB (104,857,600 bytes) also returned 404 and reduced free space from 919 MB to 819 MB. The persistent write therefore scales directly with the client-controlled payload size. Repeated requests could exhaust disk space and degrade the service's availability.
Solution
Upgrade to Hermes Agent version 0.21.6 or later.
Disclosure Timeline
All information within TRA advisories is provided “as is”, without warranty of any kind, including the implied warranties of merchantability and fitness for a particular purpose, and with no guarantee of completeness, accuracy, or timeliness. Individuals and organizations are responsible for assessing the impact of any actual or potential security vulnerability.
Tenable takes product security very seriously. If you believe you have found a vulnerability in one of our products, we ask that you please work with us to quickly resolve it in order to protect customers. Tenable believes in responding quickly to such reports, maintaining communication with researchers, and providing a solution in short order.
For more details on submitting vulnerability information, please see our Vulnerability Reporting Guidelines page.
If you have questions or corrections about this advisory, please email [email protected]
Tenable One
Request a demo
The world’s leading AI-powered exposure management platform.
Thank You
Thank you for your interest in Tenable One.
A representative will be in touch soon.
Form ID: 7469
Form Name: one-eval
Form Class: c-form form-panel__global-form c-form--mkto js-mkto-no-css js-form-hanging-label c-form--hide-comments
Form Wrapper ID: one-eval-form-wrapper
Confirmation Class: one-eval-confirmform-modal
Simulate Success