Skip to content

fix: remove hardcoded secret in ConnectionProfileOps.ts (CWE-798) - #705

Open
anupamme wants to merge 1 commit into
rockcarver:mainfrom
anupamme:fix-repo-frodo-cli-mask-log-api-key-in-conn-list
Open

anupamme wants to merge 1 commit into
rockcarver:mainfrom
anupamme:fix-repo-frodo-cli-mask-log-api-key-in-conn-list

Conversation

@anupamme

Copy link
Copy Markdown

Connection profiles store API keys, passwords, and authentication credentials in plaintext configuration files (~/.frodo/Connections.json). The code reads and displays these credentials, and while there's a masterkey.key file mentioned for decryption, the storage model relies on file system permissions for protection. This was found by static analysis at src/ops/ConnectionProfileOps.ts:56. I have not demonstrated an exploit against your deployment, so please judge it against your own threat model.

Reference: CWE-798

What changed

  • src/ops/ConnectionProfileOps.ts

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant