An empty password in connection configuration

An empty password in connection configuration

Description

Leaving password or passphrase empty in a connection that expects password authentication can cause authentication failure, or allow a connection with weak credentials if the server accepts an empty password. An empty client setting does not disable server authentication. Check the actual account's authentication method and whether the server accepts an empty value.

Potential impact

  • An account that accepts an empty password over an available connection path may permit unauthorized access.
  • Depending on the account's permissions, access may allow data retrieval, modification or deletion, mail sending or queue use.
  • If the server rejects the value, failed connections may disrupt the application.

Remediation

  • For password authentication, supply a suitably strong secret rather than an empty or default password.
  • Do not hardcode passwords in code or repositories. Load them from protected environment variables or a secret store such as AWS Secrets Manager or Vault.
  • Reject a missing or empty required password at startup, before connecting. For authentication methods that do not use a password, verify the appropriate credentials and policy instead.

Examples

Before

javascript
// Supply an empty password in configuration
const mysql = require("mysql2/promise");

const config = {
  host: "db.internal",
  user: "app_user",
  password: "", // Whether an empty password is accepted depends on server authentication
  database: "app",
};

async function connect() {
  const conn = await mysql.createConnection(config);
  console.log("connected");
}

connect().catch(console.error);

After

javascript
// Load secrets from protected configuration and reject empty required values
const mysql = require("mysql2/promise");

function requiredEnv(name) {
  const v = process.env[name];
  if (!v || v.trim().length === 0) {
    throw new Error(`Missing required secret: ${name}`);
  }
  return v;
}

const dbPassword = requiredEnv("DB_PASSWORD");

const config = {
  host: process.env.DB_HOST || "db.internal",
  user: process.env.DB_USER || "app_user",
  password: dbPassword,
  database: process.env.DB_NAME || "app",
};

async function connect() {
  const conn = await mysql.createConnection(config);
  console.log("connected");
}

connect().catch((err) => {
  // Do not log sensitive values
  console.error("DB 연결 실패:", err.message);
  process.exit(1);
});

Explanation:

  • Before: The client supplies an empty password. It connects with weak credentials if the server account accepts the value, or fails if the server rejects it.
  • After: The required password is read from the environment and checked before connecting. Protect how the variable is supplied and accessed, along with the actual server authentication settings.

References