Hacktoberfest 2026: những issue maintainer đã đánh dấu cho tháng Mười, đang mở và phù hợp người mới. Xem issue Hacktoberfest

Security(M-07): Hub OIDC login credential reused for Admin API and forwarded to japps with broad realm roles

Đang mở
#175 0 bình luận 0 reaction 0 người được giao Xem trên GitHub

Chưa có ai nhận issue này.

Đánh giá

Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức phù hợp với người mới
35/100
Loại issue
Lỗi
Độ rõ ràng
Khá rõ ràng
Mức độ hoạt động
Ít trao đổi
Công nghệ
python, yaml

Hướng nghiên cứu

Bắt đầu bằng cách đọc config/jupyterhub/00-gateway-auth.py, config/jupyterhub/02-jhub-apps.py, files/keycloak_rbac_bootstrap.py và values.yaml tại các dòng được tham chiếu. Theo dõi cách login client được sử dụng và cách secret cùng các realm role của nó được cấu hình; xác định một thiết kế đáp ứng việc tra cứu ủy quyền bắt buộc mà không để lộ thông tin xác thực quản trị. Hoàn thành khi login client không có realm-management role và không thể liệt kê các realm object không liên quan.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Mô tả

area: security priority: medium ⚡

Summary

The hub's OIDC login client doubles as its Keycloak Admin API service account, and the same client secret is forwarded into the user-facing japps service. The login client is granted broad realm-management read roles, so compromise of this widely distributed credential permits realm-wide enumeration of users, groups, clients, and configuration.

Severity: Medium · CWE-250 (Execution with Unnecessary Privileges)
Validation: Confirmed against HEAD f932d80 on 2026-07-14 (assessed at 69c84f7; unchanged since).

Evidence

  • Login credentials reused for Admin API: config/jupyterhub/00-gateway-auth.py:480-490 builds the Admin API client from the same OAuth client_id/client_secret, and _client_credentials_token (00-gateway-auth.py:149-161) performs a client_credentials grant with them.
  • Secret forwarded to japps: config/jupyterhub/02-jhub-apps.py:79-84 injects JUPYTERHUB_OIDC_CLIENT_SECRET into the japps subprocess environment.
  • Broad roles: files/keycloak_rbac_bootstrap.py:64 assigns view-clients, view-groups, view-realm, view-users. Note the values.yaml:266 comment advertises only three of these (it omits view-users), so the docs understate what the code grants.

Impact

The platform needs limited authorization-lookup capability, but binding realm-management roles to the login credential and then forwarding that credential to a user-facing service means a single compromise can enumerate every user, group, and client in the realm.

Remediation

  • Separate login credentials from administration credentials.
  • Use a purpose-specific identity or an authorization broker that exposes only the required group/profile decision.
  • Never forward administrative credentials into a user-facing service.
  • Rotate the existing secret.
  • Fix the values.yaml comment to match the roles actually granted.

Acceptance criteria

  • The login client has no realm-management roles.
  • Compromise of the login client cannot enumerate unrelated realm objects.

Source: data-science-pack 0.1.0 security assessment (pinned commit 69c84f72df259ec755ed40bfc83f20158c550d55), finding M-07.

Ngôn ngữ chính
Python
Star
5
Fork
7
Merge trung bình
20 phút
Pull request đã merge (30 ngày)
4

Chuẩn bị môi trường

Bắt đầu từ đâu

  1. Đọc hết issue, rồi đọc hướng dẫn đóng góp của dự án.
  2. Bình luận trên issue rằng bạn sẽ nhận — tránh hai người làm cùng một việc.
  3. Fork repository và làm thay đổi trên một nhánh.
  4. Mở pull request có tham chiếu số hiệu của issue.

Issue khác của nebari-dev/data-science-pack

Tất cả issue của nebari-dev/data-science-pack

Issue tương tự

Thêm issue về Python

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.