GHSA-8phw-xrj9-cpqp: Infoleak
Summary
Steeltoe's /actuator/httpexchanges endpoint records and displays request URIs after passing them through MaskedUri. The masking only covers the UserInfo portion of the URI (inline user:password@host credentials) and does not inspect the query string. With IncludeQueryString enabled by default, any secrets carried in query strings (for example: OAuth tokens, password-reset tokens, signed-URL signatures, API keys) are returned verbatim in the uri field of the response and written to logs at DEBUG level.
Impact
Any caller who can reach /actuator/httpexchanges can receive full request URIs from prior traffic, including any secrets those URIs contained in their query strings. Applications with DEBUG-level logging enabled for the Steeltoe.Management.Endpoint.Actuators.HttpExchanges namespace also write these URIs to their application logs.
Affected configuration
- httpexchanges is explicitly added to the actuator exposure list (Management:Endpoints:Web:Exposure:Include). It is not included by default. - The application handles requests that carry secrets in query strings, such as OAuth callbacks, signed URLs, or password-reset links. - DEBUG logging is enabled for Steeltoe.Management.Endpoint.Actuators.HttpExchanges (log exposure only).
Mitigations
If an immediate upgrade is not possible:
- Remove httpexchanges from the actuator exposure list, or restrict it behind authentication. - Set Management:Endpoints:HttpExchanges:IncludeQueryString to false to strip query strings from recorded exchanges entirely.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
nuget/Steeltoe.Management.Endpointto a version that resolves this vulnerability.Fixed in 4.3.0 - Configuration
Set `Management:Endpoints:HttpExchanges:IncludeQueryString` to `false` to strip query strings from recorded exchanges entirely.
Steeltoe Management - Actuators (HttpExchanges) Management:Endpoints:HttpExchanges:IncludeQueryString = false - Configuration
Remove `httpexchanges` from the actuator exposure list (`Management:Endpoints:Web:Exposure:Include`) or restrict access to the `/actuator/httpexchanges` endpoint behind authentication.
Steeltoe Management Endpoints Management:Endpoints:Web:Exposure:Include = Remove `httpexchanges` - Configuration
Disable DEBUG-level logging (or increase log level) for the `Steeltoe.Management.Endpoint.Actuators.HttpExchanges` namespace to prevent recorded request URIs (including prior query-string secrets) from being written to application logs.
Steeltoe Management - Actuators (HttpExchanges) logging DEBUG logging for `Steeltoe.Management.Endpoint.Actuators.HttpExchanges` = disable/raise log level above DEBUG
Event History
Frequently Asked Questions
Is a default Steeltoe actuator deployment exposed?
No. The httpexchanges endpoint is not included in the default actuator exposure list. Exposure requires explicitly adding httpexchanges to Management:Endpoints:Web:Exposure:Include.
What access does an attacker need to retrieve leaked values?
The attacker must be able to reach the /actuator/httpexchanges endpoint. They can then receive full URIs from prior requests, including secrets present in query strings.
How can I determine whether my application is affected?
Check whether httpexchanges is explicitly exposed through Management:Endpoints:Web:Exposure:Include and whether the application processes secrets in query strings. Also check whether DEBUG logging is enabled for the Steeltoe.Management.Endpoint.Actuators.HttpExchanges namespace, as affected URIs are written to application logs at that level.