apache / apache/cloudstack

SSH key pairs are very buggy

Open
#12,925 2 comments 0 reactions 0 assignees View on GitHub
component:UI
Dominant language
Java
Stars
3.1k
Forks
1.4k
Avg merge
6d 19h
Merged PRs (30d)
32

Description

### problem

Having the ssh key pairs being identified by their name leads to a lot of weird issues.

1. The key pair validator allows commas(and other special characters like an ampersand) in the key pair name.
2. The `deployVirtualMachine` command `keypairs` parameter isn't escaped, this breaks on key pairs containing commas.
4. The `deployVirtualMachine` command `keypair` works with commas
5. The UI breaks when a key pair contains commas, below is a single key containing a bunch of commas Image
6. If the API consumer assumes the key pair name is safe and validated by cloudstack it *cloud* lead to a command injection(but it requires a lot of wrong assumptions)

### versions

CloudStack 4.22.0.0

### The steps to reproduce the bug

You can use the UI to observe most of the issues:
1. Create a new key pair with a comma in the name eg. `test, test`
2. Try creating a new instance with said key

### What to do about it?

1. Add a new `keypairId` array parameter to all the endpoint which access key pair name.
2. Mark the `keypair` and `keypairs` parameters deprecated.

Contributor guide

Open the contributing guide

Research direction

Start by tracing the API endpoints that accept or access key pair names, then reproduce the comma-containing key pair through the UI and deployVirtualMachine commands. Identify all affected endpoints and their existing keypair/keypairs parameters. Done means the required keypairId array parameters are available and the name-based parameters are marked deprecated without breaking the documented workflows.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
api, backend-api-design
Issue type
Bug
Difficulty
5/5
Estimated time
Over a week
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
43/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.