apache / apache/cloudstack

Weak Default Password on System VMs.

オープン
#14,075 コメント 1 件 リアクション 0 件 担当者 0 名 GitHub で見る
component:csvm component:ssvm component:virtual-router type:security
主要言語
Java
スター
3.1k
フォーク
1.4k
平均マージ
6日 19時間
マージ済み PR(30日)
32

説明

### The required feature described as a wish

**Description:** By default, CloudStack uses a hard-coded password for all System VMs.

**Affected Components:** System VMs (SSVM, CPVM, and VR)

**Impact:** An attacker who knows the default credentials, which are publicly documented, and has console access to any System VM could log in as `root`.

- On a VR: the attacker could act as a man-in-the-middle (MITM).
- On a SSVM: the attacker could tamper with templates and ISOs, and delete snapshots.
- On a CPVM: the attacker could potentially install a keylogger on noVNC sessions.

Steps to Reproduce:

- Open the Console of any System VM.
- Enter the default username `root` and password `password`.

**Recommended Remediation:** Enable randomization of System VM passwords by default, while allowing administrators to disable this behavior if needed.

**Note:** This feature already exists. Additionally, documentation improvements have been proposed to clarify how to enable and use it.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず、既存の System VM パスワードランダム化機能と、この issue で提案されているドキュメントを特定します。特定のファイルやテストは指定されていません。SSVM、CPVM、VR にこの動作がどのように適用されるかを、設定のデフォルト値とオプトアウトを含めて確認します。完了の条件は、パスワードがデフォルトでランダム化され、管理者が引き続きこの動作を無効化でき、使用方法が明確にドキュメント化されていることです。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
java
領域
cloud, infrastructure, security
issue の種類
機能追加
難易度
4/5
見積もり時間
3〜5日
活発さ
活発
明瞭さ
おおむね明確
初心者へのやさしさ
48/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。