[ 
https://issues.apache.org/jira/browse/HIVE-30009?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Zhihua Deng updated HIVE-30009:
-------------------------------
    Security:     (was: Non-Public)

> Standalone server ships TLS-on default with public bundled key and changeit 
> password
> ------------------------------------------------------------------------------------
>
>                 Key: HIVE-30009
>                 URL: https://issues.apache.org/jira/browse/HIVE-30009
>             Project: Hive
>          Issue Type: Bug
>            Reporter: Stamatis Zampetakis
>            Assignee: Zhihua Deng
>            Priority: Minor
>              Labels: hive/20260811T043204Z, insecure-defaults
>             Fix For: 4.3.0
>
>
> *ID:* f130 \\ *Affected code:* 
> standalone-metastore/metastore-rest-catalog/src/main/resources/application.yml:27
>  \\ *Confidence:* 0.6 \\ *Problem:* application.yml sets 
> server.ssl.enabled=true with key-store classpath:keystore.p12 and 
> key-store-password changeit; keystore.p12 is checked into src/main/resources 
> and packaged into the release jar. A self-signed dev cert would merely fail 
> verification, but a published private key lets an active MITM terminate TLS 
> indistinguishably for any client configured to trust it (and clients are 
> pushed toward trust-all/pinning-the-bundled-cert because the cert is 
> self-signed). The comment marks it "dev" but the secure-by-default appearance 
> (https scheme in the announced endpoint, RestCatalogServerRuntime:76-81) 
> makes silent production carry-over likely, and bearer JWTs for the catalog 
> transit this channel. \\ *Exploit Scenario:* Operator deploys the standalone 
> server without overriding -Dserver.ssl.key-store. A MITM on the 
> client->catalog path presents the bundled cert+key extracted from the public 
> jar, terminates TLS, harvests OAuth2/JWT bearer tokens from Authorization 
> headers, and replays them against the real server for full catalog access. \\ 
> *Preconditions:* \\ * Standalone server deployed with default SSL settings 
> (operator did not override the keystore) \\ * Attacker in an active MITM 
> position between REST clients and the server \\ * Clients trusting the 
> bundled self-signed certificate \\ *Recommendation:* A private key must never 
> ship in the artifact. Remove keystore.p12 from src/main/resources, make 
> server.ssl.enabled default to false with a hard startup failure if enabled 
> without an operator-supplied keystore, or auto-generate an ephemeral key at 
> first start; log a prominent warning when a non-operator keystore is in use. 
> \\ *Sources:* \\ * supp-iceberg-catalog-hms-rest



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to