[
https://issues.apache.org/jira/browse/HIVE-30009?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Zhihua Deng updated HIVE-30009:
-------------------------------
Security: (was: Non-Public)
> Standalone server ships TLS-on default with public bundled key and changeit
> password
> ------------------------------------------------------------------------------------
>
> Key: HIVE-30009
> URL: https://issues.apache.org/jira/browse/HIVE-30009
> Project: Hive
> Issue Type: Bug
> Reporter: Stamatis Zampetakis
> Assignee: Zhihua Deng
> Priority: Minor
> Labels: hive/20260811T043204Z, insecure-defaults
> Fix For: 4.3.0
>
>
> *ID:* f130 \\ *Affected code:*
> standalone-metastore/metastore-rest-catalog/src/main/resources/application.yml:27
> \\ *Confidence:* 0.6 \\ *Problem:* application.yml sets
> server.ssl.enabled=true with key-store classpath:keystore.p12 and
> key-store-password changeit; keystore.p12 is checked into src/main/resources
> and packaged into the release jar. A self-signed dev cert would merely fail
> verification, but a published private key lets an active MITM terminate TLS
> indistinguishably for any client configured to trust it (and clients are
> pushed toward trust-all/pinning-the-bundled-cert because the cert is
> self-signed). The comment marks it "dev" but the secure-by-default appearance
> (https scheme in the announced endpoint, RestCatalogServerRuntime:76-81)
> makes silent production carry-over likely, and bearer JWTs for the catalog
> transit this channel. \\ *Exploit Scenario:* Operator deploys the standalone
> server without overriding -Dserver.ssl.key-store. A MITM on the
> client->catalog path presents the bundled cert+key extracted from the public
> jar, terminates TLS, harvests OAuth2/JWT bearer tokens from Authorization
> headers, and replays them against the real server for full catalog access. \\
> *Preconditions:* \\ * Standalone server deployed with default SSL settings
> (operator did not override the keystore) \\ * Attacker in an active MITM
> position between REST clients and the server \\ * Clients trusting the
> bundled self-signed certificate \\ *Recommendation:* A private key must never
> ship in the artifact. Remove keystore.p12 from src/main/resources, make
> server.ssl.enabled default to false with a hard startup failure if enabled
> without an operator-supplied keystore, or auto-generate an ephemeral key at
> first start; log a prominent warning when a non-operator keystore is in use.
> \\ *Sources:* \\ * supp-iceberg-catalog-hms-rest
--
This message was sent by Atlassian Jira
(v8.20.10#820010)