Executive brief
Apache SkyWalking NodeJS Agent is a performance monitoring tool that collects telemetry data from Node.js applications. A flaw in how the agent handles malformed SkyWalking headers can cause it to crash, making the instrumented application unavailable when the monitoring backend is unhealthy. An attacker could send HTTP requests with crafted headers to trigger this crash.
Technical details
The vulnerability is a denial-of-service condition in Apache SkyWalking NodeJS Agent versions prior to 0.5.1. When the agent receives an HTTP request containing an illegal or malformed SkyWalking header and cannot connect to the OAP (Observation Analysis Platform) backend due to it being unhealthy, the agent crashes instead of gracefully handling the error, causing the entire instrumented Node.js service to become unavailable. The attack requires network access to send HTTP requests but no authentication or special privileges. The vulnerability was patched in version 0.5.1.
Affected products
- Apache SkyWalking NodeJS Agent prior to 0.5.1
Timeline
- 2022-07-19: disclosed
- 2022-07-19: patched: version 0.5.1 released