Update remediating-the-xz-vulnerability-with-fleet.md (#32771)

Updated article with policy failure script execution features added in
Fleet version 4.58
This commit is contained in:
Brock Walters
2025-09-17 08:43:54 -04:00
committed by GitHub
parent aa663e2344
commit f1ec163606
@@ -2,24 +2,23 @@
![Remediating the xz vulnerability with Fleet](../website/assets/images/articles/discovering-geacon-using-fleet-1600x900@2x.jpg)
Detecting and remediating software vulnerabilities is more crucial than ever.
Detecting and remediating software vulnerabilities is more critical than ever.
`CVE-2024-3094` recently exposed a critical vulnerability in the `xz` libraries. This vulnerability, which can open backdoors on systems with `xz` installed starting from version 5.6.0, particularly affects `sshd` authentication.
`CVE-2024-3094` exposed a vulnerability in the `xz` libraries. This vulnerability, which can open backdoors on systems with `xz` installed starting from version 5.6.0, particularly affects `sshd` authentication.
Fleet is known for its ability to provide real-time insights and manage devices across platforms.
Because of this, we wanted to test using Fleet to build an end-to-end remediation workflow for `CVE-2024-3094`. The following case study looks at Fleets strengths and some areas where improvements could be made when using Fleet for this type of remediation.
## Discovery
The initial step involved leveraging Fleet's quick search capability, known as _live query_, to locate `xz` on Fleets computers.
This underscored Fleet's strength in identifying vulnerable software. It also revealed a limitation: out-of-the-box software search capabilities in the Fleet UI only gathered information about `xz`via the <code>[homebrew_packages](https://fleetdm.com/tables/homebrew_packages)</code> osquery table.
This highlights Fleet's strength in identifying vulnerable software. It also revealed a limitation: out-of-the-box software search capabilities in the Fleet UI only gathered information about `xz` via the <code>[homebrew_packages](https://fleetdm.com/tables/homebrew_packages)</code> osquery table.
By adding saved queries like the ones below, Fleet can be customized to search for software like `xz` in more places across multiple computer platforms:
**This query checks for libraries related to xz on a Linux system:**
@@ -31,9 +30,9 @@ UNION ALL
SELECT * FROM programs WHERE name LIKE '%xz%';
```
> Running queries with wildcards may greatly impact Fleet Host performance.
**This query checks for xz installations on a Linux system:**
@@ -77,15 +76,12 @@ SELECT * FROM syslog WHERE message LIKE '%xz%';
SELECT * FROM file_events WHERE target_path LIKE '%/xz';
```
> Enabling File Integrity Monitoring requires modification of the Fleet configuration. For more information, see [file integrity monitoring (FIM)](https://fleetdm.com/guides/osquery-evented-tables-overview?utm_source=fleetdm.com&utm_content=table-yara_events#file-integrity-monitoring-fim) in the Fleet documentation for more information.
For more information on gathering data from Fleet Hosts, see the [Fleet osquery table schema documentation.](https://fleetdm.com/tables/account_policy_data)
## Remediation
### Policy logic
Fleets Policy feature allows admins to craft custom SQL queries that run on Hosts enrolled in Fleet. A Policy is effectively a pass/fail test based on a query result.
@@ -96,26 +92,19 @@ In some use cases, SQL query logic is not always well-suited for returning pass
The Policy should fail _if and only if_ the targeted file is found.
![Policy screenshot - remediate xz version 5.6.0 & 5.6.1](../website/assets/images/articles/discovering-xz-vulnerability-with-fleet-2-1522x822@2x.png "Policy screenshot - remediate xz version 5.6.0 & 5.6.1")
**Query explanation:**
Query explanation:
* The “inner” query returns true if the file exists
* The “outer” query returns the value 1 if the “inner” query determination is false
* The “inner” query `(SELECT 1 FROM homebrew_packages WHERE name = 'xz' AND version >= '5.6.0')` returns true if the file exists
* The “outer” query `SELECT 1 WHERE NOT EXISTS` returns the value 1 if the “inner” query determination is false
A Policy failure event generates the webhook to trigger our remediation automation.
### Scripts
Below is a script that will:
* Determine if the `xz` package was installed via Homebrew
* Update Homebrew if `xz` is detected
@@ -152,37 +141,18 @@ else
fi
```
Integrating a third-party automation solution is required to execute this script if it is stored in Fleet. To complete the remediation workflow, the third-party solution must:
* Receive the webhook sent from the Fleet Policy failure event
* Use the webhook as a trigger to send an HTTP request to the Fleet API to execute the script
Here is a [Tines](https://www.tines.com/) workflow integration that performs these steps, remediating vulnerable Fleet Hosts:
![Example Tines webhook workflow to run script](../website/assets/images/articles/discovering-xz-vulnerability-with-fleet-1-1102x876@2x.png "Example Tines webhook workflow to run script")
It is non-optimal to require a 3rd party solution for executing scripts. It would be ideal to have the ability in Fleet to find and remediate vulnerable Hosts via a Fleet-only workflow.
> Fleet added the ability to automatically execute scripts on Policy failures in version 4.58 - see: https://fleetdm.com/guides/policy-automation-run-script for more infromation.
## Opportunities
This case study illuminates Fleet's capabilities and, hopefully, will open a dialogue for improvement in the following areas:
* Enhancing Fleet UI search capabilities
* Simplifying Fleet Policy features to allow for more intuitive query logic
* Adding Script execution capabilities in Fleet to streamline admin workflows
Efforts to mitigate the `xz` vulnerability at Fleet allowed us to gain valuable insights. By acknowledging current capability limitations, we intend to pave the way for future enhancements that will make Fleet a comprehensive device management solution - much more than just a tool for detection and data collection.
<meta name="articleTitle" value="Remediating the xz vulnerability with Fleet">
<meta name="authorFullName" value="Brock Walters">
<meta name="authorGitHubUsername" value="nonpunctual">