apache / apache/cloudstack

SSH key pairs are very buggy

Offen
#12,925 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
component:UI
Vorherrschende Sprache
Java
Sterne
3.1k
Forks
1.4k
Ø Merge
6 T. 19 Std.
Gemergte PRs (30 T.)
32

Beschreibung

### problem

Having the ssh key pairs being identified by their name leads to a lot of weird issues.

1. The key pair validator allows commas(and other special characters like an ampersand) in the key pair name.
2. The `deployVirtualMachine` command `keypairs` parameter isn't escaped, this breaks on key pairs containing commas.
4. The `deployVirtualMachine` command `keypair` works with commas
5. The UI breaks when a key pair contains commas, below is a single key containing a bunch of commas Image
6. If the API consumer assumes the key pair name is safe and validated by cloudstack it *cloud* lead to a command injection(but it requires a lot of wrong assumptions)

### versions

CloudStack 4.22.0.0

### The steps to reproduce the bug

You can use the UI to observe most of the issues:
1. Create a new key pair with a comma in the name eg. `test, test`
2. Try creating a new instance with said key

### What to do about it?

1. Add a new `keypairId` array parameter to all the endpoint which access key pair name.
2. Mark the `keypair` and `keypairs` parameters deprecated.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Beginnen Sie damit, die API-Endpunkte nachzuverfolgen, die Schlüsselpaar-Namen akzeptieren oder auf sie zugreifen, und reproduzieren Sie dann das Schlüsselpaar mit Komma über die UI und die deployVirtualMachine-Befehle. Identifizieren Sie alle betroffenen Endpunkte und ihre vorhandenen keypair/keypairs-Parameter. Als erledigt gilt die Aufgabe, wenn die erforderlichen keypairId-Array-Parameter verfügbar sind und die namensbasierten Parameter als deprecated gekennzeichnet sind, ohne die dokumentierten Workflows zu beeinträchtigen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
java
Bereich
api, backend-api-design
Issue-Typ
Bug
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
43/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.