Description
This occurs when credentials, such as passwords or authentication keys, are embedded directly in source code.
Potential impact
- Exposed credentials can give an attacker unauthorized access to protected functions or data.
- If the account has elevated privileges, those privileges can be abused.
Remediation
- Keep credentials in an access-controlled secret store or inject them through deployment configuration. Do not commit their actual values. Revoke and replace exposed credentials.
- Use established password verification features, such as Spring Security's
PasswordEncoder, for user authentication. - Store user passwords with a suitable one-way password hash, rather than reversible encryption or plaintext.
Examples
Before
java
@RestController
public class LoginController {
private static final String USERNAME = "admin";
private static final String PASSWORD = "admin123"; // Hard-coded password
@PostMapping("/login")
public String login(@RequestParam String username, @RequestParam String password) {
if (USERNAME.equals(username) && PASSWORD.equals(password)) {
return "로그인 성공";
}
return "로그인 실패";
}
}
After
java
@RestController
public class LoginController {
@Value("${credentials.username}")
private String username;
@Value("${credentials.password}")
private String password;
@PostMapping("/login")
public String login(@RequestParam String username, @RequestParam String password) {
if (this.username.equals(username) && this.password.equals(password)) {
return "로그인 성공";
}
return "로그인 실패";
}
}
Explanation:
- Before: Anyone with access to the code can read the embedded password.
- After:
@Valueillustrates reading external configuration. Keep actual passwords out of committed configuration files, and protect their delivery and access. The plaintext comparison is not a complete login implementation; user authentication needs appropriate password-hash verification.
Related CVEs
- CVE-2022-29953: Hard-coded credentials in a Condition Monitor firmware maintenance interface
- CVE-2022-29960: Hard-coded cryptographic keys in an Engineering Workstation can allow unauthorized filesystem access and privilege escalation
- CVE-2022-29964: Hard-coded passwords for local shell access in a Distributed Control System (DCS)