Weak Default Password on System VMs.
- 主要言語
- Java
- スター
- 3.1k
- フォーク
- 1.4k
- 平均マージ
- 6日 19時間
- マージ済み PR(30日)
- 32
説明
### The required feature described as a wish
**Description:** By default, CloudStack uses a hard-coded password for all System VMs.
**Affected Components:** System VMs (SSVM, CPVM, and VR)
**Impact:** An attacker who knows the default credentials, which are publicly documented, and has console access to any System VM could log in as `root`.
- On a VR: the attacker could act as a man-in-the-middle (MITM).
- On a SSVM: the attacker could tamper with templates and ISOs, and delete snapshots.
- On a CPVM: the attacker could potentially install a keylogger on noVNC sessions.
Steps to Reproduce:
- Open the Console of any System VM.
- Enter the default username `root` and password `password`.
**Recommended Remediation:** Enable randomization of System VM passwords by default, while allowing administrators to disable this behavior if needed.
**Note:** This feature already exists. Additionally, documentation improvements have been proposed to clarify how to enable and use it.
コントリビューションガイド
調査の方向性
まず、既存の System VM パスワードランダム化機能と、この issue で提案されているドキュメントを特定します。特定のファイルやテストは指定されていません。SSVM、CPVM、VR にこの動作がどのように適用されるかを、設定のデフォルト値とオプトアウトを含めて確認します。完了の条件は、パスワードがデフォルトでランダム化され、管理者が引き続きこの動作を無効化でき、使用方法が明確にドキュメント化されていることです。
索引モデルが issue の本文から書いたものです。
評価
- 技術スタック
- java
- 領域
- cloud, infrastructure, security
- issue の種類
- 機能追加
- 難易度
- 4/5
- 見積もり時間
- 3〜5日
- 活発さ
- 活発
- 明瞭さ
- おおむね明確
- 初心者へのやさしさ
- 48/100