[ 
https://issues.apache.org/jira/browse/ATLAS-5418?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Sheetal Shah resolved ATLAS-5418.
---------------------------------
    Fix Version/s: 3.0.0
       Resolution: Fixed

> v1 entity audit endpoint bypasses entity read authorization
> -----------------------------------------------------------
>
>                 Key: ATLAS-5418
>                 URL: https://issues.apache.org/jira/browse/ATLAS-5418
>             Project: Atlas
>          Issue Type: Bug
>          Components:  atlas-core
>            Reporter: Sheetal Shah
>            Assignee: Sheetal Shah
>            Priority: Major
>             Fix For: 3.0.0
>
>          Time Spent: 20m
>  Remaining Estimate: 0h
>
> h3. Summary
> v1 entity audit API missing ENTITY_READ check allows unprivileged users to 
> read audit history
> ----
> h3. Description
> The v1 endpoint {{GET /api/atlas/entities/\{guid}/audit}} returns entity 
> audit events without performing entity read authorization. It reads the audit 
> repository directly after Spring Security authentication only.
> The v2 endpoint {{GET /api/atlas/v2/entity/\{guid}/audit}} enforces the same 
> entity read access as other v2 read paths (including a path for purged 
> entities via audit metadata).
> An authenticated user who is denied entity read on v2 can still retrieve full 
> v1 audit history (including attribute snapshots in event details) if they 
> know the entity GUID.
> Impact: Unauthorized disclosure of metadata change history and historical 
> attribute values to any logged-in user without ENTITY_READ on that entity.
> Affected code (reference): {{EntityResource.getAuditEvents()}} — no 
> {{AtlasAuthorizationUtils}} / entity read check before 
> {{{}entityAuditRepository.listEvents(){}}}. v2: 
> {{EntityREST.getAuditEvents()}} performs authorization before listing events.
> ----
> h3. Environment (example — adjust as needed)
>  * Apache Atlas 3.0.0-SNAPSHOT (local deploy)
>  * File authentication + simple authorizer
>  * Config under {{{}{ATLAS_HOME}/conf/{}}}:
>  ** {{{}atlas-application.properties{}}}: 
> {{{}atlas.authentication.method.file=true{}}}, 
> {{atlas.authorizer.impl=simple}}
>  ** {{{}users-credentials.properties{}}}: {{admin}} and unprivileged test 
> user {{bob}}
>  ** {{{}atlas-simple-authz-policy.json{}}}: {{admin}} in {{{}userRoles{}}}; 
> {{bob}} not in {{userRoles}}
> ----
> h3. Steps to reproduce
>  # Configure auth and authorization
>  ** In {{{}conf/atlas-application.properties{}}}, enable file auth and simple 
> authorizer (see above).
>  ** In {{{}conf/users-credentials.properties{}}}, ensure {{admin}} exists and 
> add a test user, e.g.
>  {{bob=NOBODY::<sha256-hex-of-password>}}
>  (generate with {{{}echo -n 'bobpass' | shasum -a 256{}}}).
>  ** In {{{}conf/atlas-simple-authz-policy.json{}}}, map only {{admin}} to 
> {{ROLE_ADMIN}} in {{{}userRoles{}}}. Do not add {{bob}} to {{userRoles}} or 
> {{{}groupRoles{}}}.
>  ** Restart Atlas.
>  # Create a test entity (as admin)
> {{export ATLAS=http://localhost:21000
> QN="triage_$(date +%s)@cl1"
> curl -s -u admin:<admin-password> -H 'Content-Type: application/json' \
>   -X POST "$ATLAS/api/atlas/v2/entity/bulk" \
>   -d 
> "\{\"entities\":[{\"typeName\":\"hive_db\",\"attributes\":{\"qualifiedName\":\"${QN}\",\"name\":\"triage\",\"clusterName\":\"cl1\"}}]}"}}
> Note the returned GUID.
>  # Confirm bob is denied on v2 read paths
> {{export GUID=<entity-guid>
> BOB=bob:<bob-password>
> curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB 
> "$ATLAS/api/atlas/v2/entity/guid/$GUID"
> curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB 
> "$ATLAS/api/atlas/v2/entity/$GUID/audit?count=20"}}
> Observed: HTTP 403 for both.
>  # Call v1 audit as bob
> {{curl -s -o /dev/null -w '%\{http_code}\n' -u $BOB 
> "$ATLAS/api/atlas/entities/$GUID/audit?count=20"}}
> Observed: HTTP 200 with audit events in the response body.
>  # Optional control — unauthenticated v1 audit
> {{curl -s -o /dev/null -w '%\{http_code}\n' 
> "$ATLAS/api/atlas/entities/$GUID/audit?count=20"}}
> Observed: HTTP 401.
> ----
> h3. Expected result
> All entity audit read paths should require ENTITY_READ (same as v2). Bob 
> should receive 403 on v1 audit when v2 entity read and v2 audit return 403.
> ----
> h3. Actual result
> v1 audit returns 200 to bob while v2 entity read and v2 audit return 403. 
> Only authentication is enforced on v1 audit, not entity read authorization.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to