Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

Security(M-07): Hub OIDC login credential reused for Admin API and forwarded to japps with broad realm roles

Aperta
#175 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
5/5
Tempo stimato
Più di una settimana
Idoneità per principianti
35/100
Tipo di issue
Bug
Chiarezza
Abbastanza chiara
Stato di attività
Tranquilla
Stack tecnologico
python, yaml

Direzione di ricerca

Inizia leggendo config/jupyterhub/00-gateway-auth.py, config/jupyterhub/02-jhub-apps.py, files/keycloak_rbac_bootstrap.py e values.yaml alle righe indicate. Analizza come viene utilizzato il client di accesso e come sono configurati il suo secret e i suoi ruoli realm; individua un design che soddisfi la lookup di autorizzazione richiesta senza esporre credenziali amministrative. Il lavoro è completato quando il client di accesso non ha ruoli realm-management e non può enumerare oggetti realm non correlati.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

area: security priority: medium ⚡

Summary

The hub's OIDC login client doubles as its Keycloak Admin API service account, and the same client secret is forwarded into the user-facing japps service. The login client is granted broad realm-management read roles, so compromise of this widely distributed credential permits realm-wide enumeration of users, groups, clients, and configuration.

Severity: Medium · CWE-250 (Execution with Unnecessary Privileges)
Validation: Confirmed against HEAD f932d80 on 2026-07-14 (assessed at 69c84f7; unchanged since).

Evidence

  • Login credentials reused for Admin API: config/jupyterhub/00-gateway-auth.py:480-490 builds the Admin API client from the same OAuth client_id/client_secret, and _client_credentials_token (00-gateway-auth.py:149-161) performs a client_credentials grant with them.
  • Secret forwarded to japps: config/jupyterhub/02-jhub-apps.py:79-84 injects JUPYTERHUB_OIDC_CLIENT_SECRET into the japps subprocess environment.
  • Broad roles: files/keycloak_rbac_bootstrap.py:64 assigns view-clients, view-groups, view-realm, view-users. Note the values.yaml:266 comment advertises only three of these (it omits view-users), so the docs understate what the code grants.

Impact

The platform needs limited authorization-lookup capability, but binding realm-management roles to the login credential and then forwarding that credential to a user-facing service means a single compromise can enumerate every user, group, and client in the realm.

Remediation

  • Separate login credentials from administration credentials.
  • Use a purpose-specific identity or an authorization broker that exposes only the required group/profile decision.
  • Never forward administrative credentials into a user-facing service.
  • Rotate the existing secret.
  • Fix the values.yaml comment to match the roles actually granted.

Acceptance criteria

  • The login client has no realm-management roles.
  • Compromise of the login client cannot enumerate unrelated realm objects.

Source: data-science-pack 0.1.0 security assessment (pinned commit 69c84f72df259ec755ed40bfc83f20158c550d55), finding M-07.

Lingua principale
Python
Stelle
5
Fork
7
Merge medio
20m
PR unite (30g)
4

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di nebari-dev/data-science-pack

Tutte le issue di nebari-dev/data-science-pack

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.