Executive brief
Rendertron is a headless Chrome rendering service used to generate page snapshots and pre-render content for web applications. An unprotected administrative endpoint allows any remote attacker to send a single HTTP request and shut down the entire Chrome instance, causing a complete denial of service to all users relying on the rendering service.
Technical details
The vulnerability is an improper access control flaw (CWE-284) in the _ah/stop endpoint of Rendertron 1.0.0. This endpoint is responsible for gracefully shutting down the Chrome rendering process but lacks authentication and authorization checks. An attacker can reach this route over the network without credentials or user interaction by simply issuing an HTTP GET request. Successful exploitation immediately terminates the Chrome process, rendering the entire rendering service unavailable to all users. The fix, released in version 1.1.0, restricts exposure of the _ah/stop route to development environments only (when NODE_ENV is set to development), preventing remote exploitation in production deployments.
Affected products
- Google rendertron < 1.1.0
Timeline
- 2019-01-04: disclosed
- 2017-08-30: patched: Fix released in version 1.1.0