Summary
The redfish-* checks discover sub-resources by following @odata.id hypermedia links returned by the monitored controller (BMC). Each link was turned into the next request URL by string concatenation onto the operator-supplied base URL (f'{args.URL}{member["@odata.id"]}'), with no validation that @odata.id is a server-relative path. A malicious or compromised BMC can return a value beginning with @ (or //) so that the concatenated string carries an attacker-chosen authority, e.g. https://bmc + @evil/x = https://bmc@evil/x (host evil). The plugin then issues an authenticated request (Redfish X-Auth-Token session token, or HTTP Basic header) to the attacker-named host.
Impact
A malicious or compromised monitored BMC can coerce the monitoring host into issuing authenticated requests to arbitrary reachable hosts and ports (a blind SSRF pivot into the management network) and can exfiltrate the Redfish auth header. Requires a controller that returns hostile responses; the base URL is the documented path-less form (--url=https://bmc), so no extra misconfiguration is needed. Present since the redfish plugins were introduced.
Patches
Fixed in v7.0.0. Every response-supplied link is now built through lib.redfish.build_url(), which rejects any @odata.id that is not a single-slash-rooted relative path and pins scheme and host to the operator-supplied base URL, so a response can never redirect the request to another host (monitoring-plugins commit ffb0a81, linuxfabrik-lib adds the helper).
Summary
The
redfish-*checks discover sub-resources by following@odata.idhypermedia links returned by the monitored controller (BMC). Each link was turned into the next request URL by string concatenation onto the operator-supplied base URL (f'{args.URL}{member["@odata.id"]}'), with no validation that@odata.idis a server-relative path. A malicious or compromised BMC can return a value beginning with@(or//) so that the concatenated string carries an attacker-chosen authority, e.g.https://bmc+@evil/x=https://bmc@evil/x(hostevil). The plugin then issues an authenticated request (RedfishX-Auth-Tokensession token, or HTTP Basic header) to the attacker-named host.Impact
A malicious or compromised monitored BMC can coerce the monitoring host into issuing authenticated requests to arbitrary reachable hosts and ports (a blind SSRF pivot into the management network) and can exfiltrate the Redfish auth header. Requires a controller that returns hostile responses; the base URL is the documented path-less form (
--url=https://bmc), so no extra misconfiguration is needed. Present since the redfish plugins were introduced.Patches
Fixed in v7.0.0. Every response-supplied link is now built through
lib.redfish.build_url(), which rejects any@odata.idthat is not a single-slash-rooted relative path and pins scheme and host to the operator-supplied base URL, so a response can never redirect the request to another host (monitoring-plugins commit ffb0a81, linuxfabrik-lib adds the helper).