Junglewise Threat Intelligence

CVE-2017-18353: Google rendertron unauthorized Chrome shutdown via _ah/stop route

CVE-2017-18353 · Severity: low · CVSS 3 · Published 2019-01-04

Technologies: rendertron (npm). Vendors: Google, npm.

Executive brief

Rendertron is a headless Chrome rendering service used to generate page snapshots and pre-render content for web applications. An unprotected administrative endpoint allows any remote attacker to send a single HTTP request and shut down the entire Chrome instance, causing a complete denial of service to all users relying on the rendering service.

Technical details

The vulnerability is an improper access control flaw (CWE-284) in the _ah/stop endpoint of Rendertron 1.0.0. This endpoint is responsible for gracefully shutting down the Chrome rendering process but lacks authentication and authorization checks. An attacker can reach this route over the network without credentials or user interaction by simply issuing an HTTP GET request. Successful exploitation immediately terminates the Chrome process, rendering the entire rendering service unavailable to all users. The fix, released in version 1.1.0, restricts exposure of the _ah/stop route to development environments only (when NODE_ENV is set to development), preventing remote exploitation in production deployments.

Affected products

  • Google rendertron < 1.1.0

Timeline

  • 2019-01-04: disclosed
  • 2017-08-30: patched: Fix released in version 1.1.0

References

Related threats