Skip to content

Passwordless SSH access when gluon-authorized-keys was used without gluon-setup-mode

Moderate
mweinelt published GHSA-96wm-xfjr-2qx3 Jul 6, 2019 · 1 comment

Package

gluon-authorized-keys (Gluon)

Affected versions

v2015.1 - v2018.2.2

Patched versions

v2018.2.3, v2019.1

Description

Impact

Using gluon-authorized-keys without gluon-setup-mode lacked a dependency on gluon-lock-password, which led to passwordless SSH access to nodes. This is especially problematic, as setting up authorized SSH keys would lead people to believe that it would securely configure the node to be only accessed this way.

This is a very uncommon setup, as gluon-setup-mode is the basis for config mode, which is commonly used.

Patches

Workarounds

Execute passwd -l root on affected nodes.

References

#1777

For more information

If you have any questions or comments about this advisory:

  • Use the existing issue at #1777

Severity

Moderate

CVE ID

No known CVE

Weaknesses

No CWEs

Credits