28Hus opened a new issue, #1557:
URL: https://github.com/apache/dubbo-admin/issues/1557

   # Hard-coded session signing key allows authentication bypass in Go-based 
Dubbo Admin
   
   ## Summary
   
   The Go-based Dubbo Admin hard-codes the signing key used by its client-side 
session cookie. The same cookie store is used by the authentication middleware, 
which grants access when the session contains a `user` value. There is no 
server-side session lookup or revocation check to prevent forged cookies.
   
   The issue remains present at commit 
[1e56a0a](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86).
   
   ## Evidence
   
   The session store is initialized with a fixed value:
   
   
[pkg/console/component.go#L86](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86)
   
   The store is registered as the application-wide session middleware:
   
   
[pkg/console/component.go#L86-L88](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86-L88)
   
   The authentication middleware only checks whether `session.Get("user")` is 
present:
   
   
[pkg/console/component.go#L135-L151](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L135-L151)
   
   ## Impact
   
   An attacker who can read the public source code can generate a valid session 
cookie containing an arbitrary user value. The forged cookie is accepted as an 
authenticated session and can be used to access endpoints protected only by 
this middleware.
   
   The issue was reproduced in a controlled local deployment. A request without 
a session cookie was rejected, while a forged cookie was accepted. Detailed 
request, response, and PoC material can be provided privately.
   
   ## Timeline
   
   - **December 11, 2025:** I privately reported the hard-coded session signing 
key and the lack of server-side validation to the Apache and Dubbo security 
teams.
   - **January 12, 2026:** Dubbo Admin published the public pre-release 
`v0.7.0-pre`.
   - **March-April 2026:** Follow-ups confirmed that the hard-coded key 
remained present. I also offered to prepare a pull request with a remediation. 
No response was received to these follow-ups as of September 15, 2026.
   - **September 15, 2026:** The key remains present at commit 
[1e56a0a](https://github.com/apache/dubbo-admin/blob/1e56a0a7c2e8bd7921b7d03159a9f80645486270/pkg/console/component.go#L86).
 This public Issue is opened to request project attention and coordinate a fix.
   
   ## Recommended Fix
   
   Remove the hard-coded session signing key. The application should require a 
deployment-specific cryptographically random secret, generate one during 
installation, or fail startup when no secure value is configured.
   
   
   ## Collaboration
   
   This Issue requests clarification and coordinates remediation following the 
previous private disclosure. I will prepare a pull request or provide a patch 
through the channel preferred by the maintainers.
   
   This issue is part of my ongoing research. If you have any questions about 
this report, please feel free to @mention me at any time. I would be very happy 
to assist with improving the security of Dubbo Admin.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to