Git worktree directories created with chmod 777 (CWE-732)
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 76/100
Direzione di ricerca
Inizia da st2common/st2common/runners/base.py alle righe 385-387 e traccia il modo in cui viene creato il percorso del worktree git e passato a chmod. Verifica i permessi risultanti e il comportamento del comando per un worktree, inclusa l’assenza di shell=True. Il lavoro è completato quando l’accesso al worktree è limitato agli utenti richiesti senza esporre il codice dell’azione ad altri utenti locali.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Summary
When StackStorm creates git worktree directories for pack content versioning, it sets the permissions to 777 (world-readable, world-writable, world-executable). This allows any user on the system to read or tamper with action code before it executes.
Affected File
st2common/st2common/runners/base.py (lines 385-387)
# Make sure system / action runner user can access that directory
args = ["chmod", "777", worktree_path]
cmd = list2cmdline(args)
run_command(cmd=cmd, shell=True)
This also unnecessarily uses shell=True for a simple chmod operation.
Impact
The worktree directory contains the action code that will be executed by the action runner. With 777 permissions:
-
Code tampering: Any local user can modify the action scripts in the worktree between creation and execution, achieving arbitrary code execution in the context of the StackStorm action runner.
-
Information disclosure: Any local user can read the action code, which may contain embedded configuration, API endpoints, or logic that should not be broadly accessible.
-
Race condition: Since the worktree is created and then permissions are set in a separate step, there is a window where the directory exists with its original permissions before being opened up.
Recommended Fix
Use the minimum necessary permissions. The directory only needs to be accessible by the StackStorm system user and the action runner user:
# Use 750 (owner: rwx, group: r-x, other: none) or 770 if group write is needed
args = ["chmod", "750", worktree_path]
Or better, set ownership and permissions atomically:
import os
import stat
os.chmod(worktree_path, stat.S_IRWXU | stat.S_IRGRP | stat.S_IXGRP) # 750
This also eliminates the need for shell=True and the subprocess call entirely.
References
- CWE-732: Incorrect Permission Assignment for Critical Resource
- Discovered via manual code review
- Lingua principale
- Python
- Stelle
- 6.5k
- Fork
- 787
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di StackStorm/st2
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 86/100
StackStorm/st2#6393 · 1 commento ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 76/100
StackStorm/st2#6389 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
StackStorm/st2#6387 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 55/100
StackStorm/st2#6391 ·
-
CORS middleware reflects Origin with Allow-Credentials, enabling cross-origin attacks (CWE-346)Aperta
Difficoltà 3/5 1-2 giorni Idoneità per principianti 68/100
StackStorm/st2#6390 ·
Tutte le issue di StackStorm/st2
Issue simili
-
adr
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
kristofdegrave/homeassistant-smart-charging#1607 ·
I maintainer di solito rispondono entro 1 giorno
-
namespace operations
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
EclipseFdn/open-vsx.org#13665 ·
I maintainer di solito rispondono entro 1 giorno
-
doc good first issue help wanted
Difficoltà 2/5 1-3 ore Idoneità per principianti 68/100
collective/icalendar#1865 · 2 commenti ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 82/100
canonical/opentelemetry-collector-operator#409 ·
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 85/100
mozilla/addons-release-tests#1243 ·
I maintainer di solito rispondono entro 1 giorno