Weak Default Password on System VMs.
- Ngôn ngữ chính
- Java
- Star
- 3.1k
- Fork
- 1.4k
- Merge trung bình
- 6 ngày 19 giờ
- Pull request đã merge (30 ngày)
- 32
Mô tả
### The required feature described as a wish
**Description:** By default, CloudStack uses a hard-coded password for all System VMs.
**Affected Components:** System VMs (SSVM, CPVM, and VR)
**Impact:** An attacker who knows the default credentials, which are publicly documented, and has console access to any System VM could log in as `root`.
- On a VR: the attacker could act as a man-in-the-middle (MITM).
- On a SSVM: the attacker could tamper with templates and ISOs, and delete snapshots.
- On a CPVM: the attacker could potentially install a keylogger on noVNC sessions.
Steps to Reproduce:
- Open the Console of any System VM.
- Enter the default username `root` and password `password`.
**Recommended Remediation:** Enable randomization of System VM passwords by default, while allowing administrators to disable this behavior if needed.
**Note:** This feature already exists. Additionally, documentation improvements have been proposed to clarify how to enable and use it.
Hướng dẫn đóng góp
Hướng nghiên cứu
Bắt đầu bằng cách xác định tính năng hiện có để ngẫu nhiên hóa mật khẩu của System VM và tài liệu được đề xuất trong issue này; không có tệp hoặc bài kiểm tra cụ thể nào được nêu tên. Kiểm tra cách hành vi này áp dụng cho SSVM, CPVM và VR, bao gồm giá trị mặc định của cấu hình và tùy chọn tắt. Được xem là hoàn thành khi mật khẩu được ngẫu nhiên hóa theo mặc định, quản trị viên vẫn có thể tắt hành vi này và cách sử dụng được ghi tài liệu rõ ràng.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- java
- Lĩnh vực
- cloud, infrastructure, security
- Loại issue
- Tính năng
- Độ khó
- 4/5
- Thời gian dự kiến
- 3-5 ngày
- Mức độ hoạt động
- Sôi nổi
- Độ rõ ràng
- Khá rõ ràng
- Mức phù hợp với người mới
- 48/100