Hard-coded credentials

Use of Hard-coded Credentials

Description

This occurs when credentials, such as passwords or authentication keys, are embedded directly in source code.

Potential impact

  • Exposed credentials can give an attacker unauthorized access to protected functions or data.
  • If the account has elevated privileges, those privileges can be abused.

Remediation

  • Keep credentials in an access-controlled secret store or inject them through deployment configuration. Do not commit their actual values. Revoke and replace exposed credentials.
  • Use established password verification features, such as Spring Security's PasswordEncoder, for user authentication.
  • Store user passwords with a suitable one-way password hash, rather than reversible encryption or plaintext.

Examples

Before

java
@RestController
public class LoginController {

    private static final String USERNAME = "admin";
    private static final String PASSWORD = "admin123"; // Hard-coded password

    @PostMapping("/login")
    public String login(@RequestParam String username, @RequestParam String password) {
        if (USERNAME.equals(username) && PASSWORD.equals(password)) {
            return "로그인 성공";
        }
        return "로그인 실패";
    }
}

After

java
@RestController
public class LoginController {

    @Value("${credentials.username}")
    private String username;

    @Value("${credentials.password}")
    private String password;

    @PostMapping("/login")
    public String login(@RequestParam String username, @RequestParam String password) {
        if (this.username.equals(username) && this.password.equals(password)) {
            return "로그인 성공";
        }
        return "로그인 실패";
    }
}

Explanation:

  • Before: Anyone with access to the code can read the embedded password.
  • After: @Value illustrates reading external configuration. Keep actual passwords out of committed configuration files, and protect their delivery and access. The plaintext comparison is not a complete login implementation; user authentication needs appropriate password-hash verification.

Related CVEs

References