天下漏洞,尽知其名
MEDIUM

CVE-2026-104055 postgresql-operator 日志泄露密码漏洞

影响可读取日志者获取监控用户明文密码,获得数据库只读监控权限

MEDIUM
暂无 CVSS 评分
AI 研判

postgresql-operator charm 使用 Prometheus postgres_exporter 以专用 monitoring 用户采集数据库指标。当数据库连接出错时,exporter 会把该 monitoring 用户的密码以明文写入自身日志。任何能读取这些日志的人员都可还原该密码,从而获得 PostgreSQL 的只读 pg_monitor 访问权限。

影响范围

postgresql-operator charm

受影响版本为修复前的 postgresql-operator charm;官方已在 dev 轨道(14/edge)revision 1189(arm64)、1190(amd64)以及 stable 轨道(14/stable)revision 1216(arm64)、1217(amd64)中修复。

漏洞详情

漏洞类型为敏感信息明文存储于日志(信息泄露)。成因是 postgres_exporter 在数据库连接失败的错误处理路径中,将 monitoring 用户的密码直接写入日志输出,未做脱敏。攻击者只需具备日志读取权限(如访问日志文件、日志聚合系统或容器日志),即可从错误日志中提取明文密码,并利用该凭据以 pg_monitor 角色连接数据库。

利用条件与风险

利用前提是攻击者能够读取 exporter 产生的日志,且日志中已出现连接错误记录。实战中该凭据仅提供只读监控权限,但可用于信息收集,为后续攻击提供跳板,风险等级为中。

修复建议

官方修复方案为升级到 dev 轨道(14/edge)revision 1189/1190 或 stable 轨道(14/stable)revision 1216/1217 及之后版本。临时缓解措施包括限制日志访问权限、避免将 exporter 日志暴露给非授权人员,并轮换已泄露的 monitoring 用户密码。

原始情报

The postgresql-operator charm runs a Prometheus postgres_exporter to collect database metrics using a dedicated “monitoring” PostgreSQL user. On database connection errors, the exporter writes the monitoring user’s password in cleartext to its logs. Any actor able to read those logs can recover the password, which grants read-only pg_monitor access to PostgreSQL. This is fixed in the dev track (14/edge) in revisions 1189 (arm64) and 1190 (amd64), and in the stable track (14/stable) in revisions 1216 (arm64) and 1217 (amd64).