Security(M-07): Hub OIDC login credential reused for Admin API and forwarded to japps with broad realm roles
Chưa có ai nhận issue này.
Đánh giá
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức phù hợp với người mới
- 35/100
- Loại issue
- Lỗi
- Độ rõ ràng
- Khá rõ ràng
- Mức độ hoạt động
- Ít trao đổi
- Công nghệ
- python, yaml
- Lĩnh vực
- authentication, authorization, security
Hướng nghiên cứu
Bắt đầu bằng cách đọc config/jupyterhub/00-gateway-auth.py, config/jupyterhub/02-jhub-apps.py, files/keycloak_rbac_bootstrap.py và values.yaml tại các dòng được tham chiếu. Theo dõi cách login client được sử dụng và cách secret cùng các realm role của nó được cấu hình; xác định một thiết kế đáp ứng việc tra cứu ủy quyền bắt buộc mà không để lộ thông tin xác thực quản trị. Hoàn thành khi login client không có realm-management role và không thể liệt kê các realm object không liên quan.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Mô tả
Summary
The hub's OIDC login client doubles as its Keycloak Admin API service account, and the same client secret is forwarded into the user-facing japps service. The login client is granted broad realm-management read roles, so compromise of this widely distributed credential permits realm-wide enumeration of users, groups, clients, and configuration.
Severity: Medium · CWE-250 (Execution with Unnecessary Privileges)
Validation: Confirmed against HEAD f932d80 on 2026-07-14 (assessed at 69c84f7; unchanged since).
Evidence
- Login credentials reused for Admin API:
config/jupyterhub/00-gateway-auth.py:480-490builds the Admin API client from the same OAuthclient_id/client_secret, and_client_credentials_token(00-gateway-auth.py:149-161) performs aclient_credentialsgrant with them. - Secret forwarded to japps:
config/jupyterhub/02-jhub-apps.py:79-84injectsJUPYTERHUB_OIDC_CLIENT_SECRETinto the japps subprocess environment. - Broad roles:
files/keycloak_rbac_bootstrap.py:64assignsview-clients,view-groups,view-realm,view-users. Note thevalues.yaml:266comment advertises only three of these (it omitsview-users), so the docs understate what the code grants.
Impact
The platform needs limited authorization-lookup capability, but binding realm-management roles to the login credential and then forwarding that credential to a user-facing service means a single compromise can enumerate every user, group, and client in the realm.
Remediation
- Separate login credentials from administration credentials.
- Use a purpose-specific identity or an authorization broker that exposes only the required group/profile decision.
- Never forward administrative credentials into a user-facing service.
- Rotate the existing secret.
- Fix the
values.yamlcomment to match the roles actually granted.
Acceptance criteria
- The login client has no realm-management roles.
- Compromise of the login client cannot enumerate unrelated realm objects.
Source: data-science-pack 0.1.0 security assessment (pinned commit 69c84f72df259ec755ed40bfc83f20158c550d55), finding M-07.
- Ngôn ngữ chính
- Python
- Star
- 5
- Fork
- 7
- Merge trung bình
- 20 phút
- Pull request đã merge (30 ngày)
- 4
Chuẩn bị môi trường
- Không có Dockerfile hay tệp Docker Compose
- Không có mẫu pull request
- Đọc hướng dẫn đóng góp
Bắt đầu từ đâu
- Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
- Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
- Fork repository và làm thay đổi trên một nhánh.
- Mở pull request có tham chiếu số hiệu của issue.
Issue khác của nebari-dev/data-science-pack
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
nebari-dev/data-science-pack#248 ·
-
Độ khó 1/5 1-3 giờ Mức phù hợp với người mới 88/100
nebari-dev/data-science-pack#243 ·
-
area: documentation 📖
Độ khó 2/5 1-2 ngày Mức phù hợp với người mới 76/100
nebari-dev/data-science-pack#209 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 86/100
nebari-dev/data-science-pack#206 ·
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 74/100
nebari-dev/data-science-pack#187 ·
Tất cả issue của nebari-dev/data-science-pack
Issue tương tự
-
repo-audit
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 75/100
scverse/repo-health#20 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
/context/prime scope override double-prefixes an entity-ref project and drops its scoped memoriesĐang mở
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 85/100
phasespace-labs/palinode#232 ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 82/100
collective/icalendar#1858 · 1 bình luận ·
Maintainer thường phản hồi trong vòng 1 ngày
-
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 68/100
Maintainer thường phản hồi trong vòng 1 ngày
-
lfx-mcp cannot supply global variables: LangflowClient drops X-LANGFLOW-GLOBAL-VAR-* from envĐang mởbug
Độ khó 2/5 1-3 giờ Mức phù hợp với người mới 78/100
langflow-ai/langflow#15496 ·
Maintainer thường phản hồi trong vòng 1 ngày