apache / apache/cloudstack

[Hardening] F-13: Weak Default Password and Database Encryption Key.

未关闭
#13,341 6 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
component:management-server type:enhancement
主要语言
Java
星标
3.1k
派生
1.4k
平均合并
6 天 19 小时
30 天内合并 PR
32

描述

### The required feature described as a wish

Image

**Description:** CloudStack ships with a default administrative password and database encryption key, both set to the string "password". Neither value is randomized at install time, and the administrator is not prompted to change them during setup. Note that the database encryption key cannot be changed afterwards.

**Affected Components:** Management

**Impact:** An attacker with knowledge of the default credentials, which are publicly documented, can authenticate to the CloudStack Management UI without any prior reconnaissance or effort. Additionally, if the database encryption key is not changed, an attacker who gains read access to the database (e.g., via SQL injection, a misconfigured backup, or direct server access) can decrypt all protected fields, including API secret keys, passwords, and other credentials, using the known default key.

**Steps to Reproduce:**
- Deploy a fresh CloudStack instance following the official documentation.
- Attempt to log in using the username `admin` and the password `password`.
- Observe that login succeeds without any prompt to change the default password.
- Separately, inspect the database encryption key on the management server:
- $ cat /etc/cloudstack/management/key
- Observe that the encryption key is set to the default value `password`.

**Recommended Remediation:** Generate a unique password and database encryption key from a reliable source of entropy during installation (before the system becomes operational). Neither value should have a usable default.

贡献指南

打开贡献指南

调研方向

从 CloudStack Management 的安装流程、management UI 登录以及 /etc/cloudstack/management/key 中的数据库密钥开始。追踪默认管理员密码和加密密钥在哪里创建和使用。完成的标准是:两个值都在运行前从可靠的熵中生成,不存在可用的默认值,并且安装行为有测试覆盖。

由索引模型根据 Issue 内容生成。

评估

技术栈
java
领域
authentication, cloud, databases, security
Issue 类型
功能
难度
5/5
预计耗时
一周以上
活跃度
活跃
描述清晰度
基本清楚
新手友好度
35/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。