Fedora Account System
Red Hat Associate
Red Hat Customer
AI_ONLY_REPORT package: cockpit-machines-348-1.el10 ------ Summary: Sensitive Data Exposure in Process List via Command-Line Arguments: password values supplied during VM create or install operations can be exposed to other local users through process command-line arguments. Requirements to exploit: An attacker needs local access to the host, the ability to inspect other processes' command-line arguments while the VM workflow is running, and a create or install operation that includes `rootPassword` and/or `userPassword`. Exposure is reduced on systems that restrict `/proc` visibility, such as `hidepid=2`. Component affected: `cockpit-machines` source in `src/libvirtApi/domain.ts` (`domainCreate()`, `domainInstall()`) and `src/scripts/install_machine.py` Version affected: `cockpit-machines-348-1.el10` Patch available: no released package fix established; proposed patch included below Version fixed: unknown Upstream coordination: Not notified. CVSS: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N - 4.7 (MEDIUM) AV:L - Exploitation requires local access to the host where Cockpit Machines is running. AC:L - The issue is a direct consequence of passing secrets on the command line; observation is straightforward when process arguments are visible. PR:L - A local account is typically required to inspect process listings or `/proc/<pid>/cmdline`. UI:N - No additional user interaction is required once the victim initiates the VM workflow. S:U - The impact remains within the same security scope. C:H - Successful exploitation can disclose VM credentials in full. I:N - This issue does not directly modify data or configuration. A:N - This issue does not directly affect service availability. Impact: Moderate. This issue can expose sensitive VM credentials, which is a meaningful confidentiality impact when reachable. However, it is not a remote flaw, it depends on local process-argument visibility and a narrow execution window, and hardened `/proc` settings can materially reduce exploitability. Under Red Hat's severity guidance, that places the issue below Important impact but above Low impact because the disclosed data can still lead to compromise of protected resources under realistic local-host conditions. Embargo: no Reason: The issue is local and configuration-dependent, practical mitigations already exist at deployment level, and the remediation is straightforward. This does not appear to require embargo handling typically reserved for higher-severity flaws. Acknowledgement: Aisle Research Vulnerability Details: Cockpit Machines passes password-bearing values through process arguments during VM creation and installation flows. In the cloud-image create path, plaintext passwords are passed directly to `openssl` on the command line. Separately, create and install flows serialize password-bearing JSON and pass it as `sys.argv[1]` to `install_machine.py`. ```ts if (args.userPassword) promises.push(spawn("session", ['openssl', 'passwd', '-5', args.userPassword])); if (args.rootPassword) promises.push(spawn("session", ['openssl', 'passwd', '-5', args.rootPassword])); ... await python.spawn( installVmScript, [JSON.stringify(args)], { err: "message", environ: ['LC_ALL=C.UTF-8'], ...(connectionName === "system" ? { superuser: "try" } : { }) }); ... return python.spawn( installVmScript, [args], { err: "message", environ: ['LC_ALL=C.UTF-8'], ...(vm.connectionName === "system" ? { superuser: "try" } : { }) }) ``` `install_machine.py` then consumes the payload from the command line: ```py logging.debug(sys.argv[1]) args = json.loads(sys.argv[1], strict=False) ``` On systems where other local users can inspect process arguments, this can disclose credentials entered for VM provisioning. The cloud-image create path clearly exposes plaintext passwords through `openssl passwd -5 <password>`. The JSON-based path exposes whatever password values are present in the serialized arguments at invocation time. Steps to reproduce: 1. Use a host where other local users can inspect process arguments, for example a default `/proc` configuration without `hidepid=2`. 2. Start a VM create or install operation in Cockpit Machines and provide `rootPassword` and/or `userPassword`. 3. While the operation is running, from a second unprivileged local account, inspect candidate processes: `ps -ef | grep -E "openssl passwd|-c $@|install_machine.py|python3"` 4. Read the command line for the relevant process: `tr '\0' ' ' < /proc/<pid>/cmdline` 5. Observe one of the following: `openssl passwd -5 <plaintext-password>` in the cloud-image create path JSON arguments containing `rootPassword` and/or `userPassword` passed to `install_machine.py` 6. If `/proc` is mounted with `hidepid=2` or similar restrictions, non-root observation may be blocked. That mitigates exposure but does not change the underlying secret-in-argv behavior. Mitigation: Until code is changed, avoid supplying sensitive passwords through these create/install flows on shared hosts where local users can inspect process arguments. Restrict `/proc` visibility, for example with `hidepid=2`, and prefer provisioning methods that do not require passing passwords on the command line. Proposed Fix: Stop passing secrets in argv. Feed password material to `openssl` on standard input and pass the JSON payload to `install_machine.py` via stdin instead of `sys.argv[1]`. ```diff diff --git a/src/libvirtApi/domain.ts b/src/libvirtApi/domain.ts @@ if (args.userPassword) promises.push(spawn("session", ['openssl', 'passwd', '-5', args.userPassword])); if (args.rootPassword) promises.push(spawn("session", ['openssl', 'passwd', '-5', args.rootPassword])); + if (args.userPassword) + promises.push(cockpit.spawn(['openssl', 'passwd', '-5', '-stdin'], { err: "message", input: args.userPassword + "\n" })); + if (args.rootPassword) + promises.push(cockpit.spawn(['openssl', 'passwd', '-5', '-stdin'], { err: "message", input: args.rootPassword + "\n" })); @@ await python.spawn( installVmScript, [JSON.stringify(args)], { + await python.spawn( + installVmScript, + [], + { err: "message", + input: JSON.stringify(args), environ: ['LC_ALL=C.UTF-8'], ...(connectionName === "system" ? { superuser: "try" } : { }) }); @@ return python.spawn( installVmScript, [args], { + return python.spawn( + installVmScript, + [], + { err: "message", + input: args, environ: ['LC_ALL=C.UTF-8'], ...(vm.connectionName === "system" ? { superuser: "try" } : { }) }) diff --git a/src/scripts/install_machine.py b/src/scripts/install_machine.py @@ -logging.debug(sys.argv[1]) - -args = json.loads(sys.argv[1], strict=False) +payload = sys.stdin.read() if len(sys.argv) == 1 else sys.argv[1] +args = json.loads(payload, strict=False) ``` ------ This report was generated using AI technology. Always review AI-generated content prior to use