apache / apache/cloudstack

Security: ACS user access to all databases

Aperta
#8,240 9 commenti 0 reazioni 0 assegnatari Vedi su GitHub
archive component:database status:needs-investigation type:security
Lingua principale
Java
Stelle
3.1k
Fork
1.4k
Merge medio
6g 19h
PR unite (30g)
32

Descrizione

##### ISSUE TYPE

* Bug Report
* Improvement Request
* Enhancement Request

##### COMPONENT NAME

~~~
Core, MySQL
~~~

##### CLOUDSTACK VERSION

~~~
4.19.0.0-snapshot.20231113
~~~

##### CONFIGURATION

##### OS / ENVIRONMENT

Ubuntu 22.04

##### SUMMARY

ACS requires access to all MySQL databases, which creates a huge security hole for a shared MySQL instance.

Trying to limit the scope of ACS access yields in the access denied error (see below).

##### STEPS TO REPRODUCE

~~~
> `sudo cloudstack-setup-databases cloud:cloud@mysql --deploy-as=root`

/usr/share/cloudstack-management/setup/create-database.sql
lines: 64-65
GRANT process ON *.* TO cloud@`localhost`;
GRANT process ON *.* TO cloud@`%`;

// This works with the full access
GRANT ALL ON *.* TO 'root'@'hyp0' WITH GRANT OPTION

// This yields in an error:
- GRANT ALL ON mysql.* TO 'root'@'hyp0' WITH GRANT OPTION
- GRANT ALL ON billing.* TO 'root'@'hyp0' WITH GRANT OPTION
- GRANT ALL ON cloud.* TO 'root'@'hyp0' WITH GRANT OPTION
- GRANT ALL ON cloud_usage.* TO 'root'@'hyp0' WITH GRANT OPTION
~~~

##### EXPECTED RESULTS

~~~
ACS configs own databases only without an error
~~~

##### ACTUAL RESULTS

~~~
ACS wants a full access and gives an error when a limited db access is provided

We apologize for below error:
table:
/usr/share/cloudstack-management/setup/create-database.sql

Error:
b"ERROR 1045 (28000) at line 64: Access denied for user 'root'@'hyp0' (using password: NO)\n"
~~~

Guida per i contributori

Apri la guida per i contributori

Direzione di ricerca

Inizia da /usr/share/cloudstack-management/setup/create-database.sql, in particolare dalle righe 64-65, e riproduci il comando di configurazione con i privilegi MySQL limitati mostrati. Traccia quali database e privilegi sono necessari ad ACS; il lavoro è completato quando la configurazione di CloudStack riesce con il solo ambito di database richiesto e senza accesso a database non correlati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Valutazione

Stack tecnologico
mysql, sql
Ambito
databases, security
Tipo di issue
Bug
Difficoltà
4/5
Tempo stimato
3-5 giorni
Stato di attività
Ferma
Chiarezza
Abbastanza chiara
Idoneità per principianti
35/100

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.