FazBrowse GitHub Viewer | Trending |
URL:
| Home
Tools: [Download Repo ZIP]   [Original HTTPS Page]

The value of hashed-password can be used to open CodeServer directly, which has security problem · Issue #7696 · coder/code-server · GitHub

Repository navigation

The value of hashed-password can be used to open CodeServer directly, which has security problem #7696

Description

Is there an existing issue for this?

  • I have searched the existing issues

OS/Web Information

  • Web Browser: Chrome 143.0.7499.170
  • Local OS: windows
  • Remote OS: ubuntu 22.04, jupyterlab service
  • Remote Architecture: x86
  • code-server --version: v4.108.0

Steps to Reproduce

  1. prepare "hashed-password" using command echo -n "xxx" | npx argon2-cli -e
  2. edit ~/.config/code-server/config.yaml,auth: password, hashed-password:"$argon2i$v=19$m=4096,t=3,p=1$xxx$xxx"
  3. start code-server using command code-server --port 7756
  4. using jupyter_server_proxy to visit code-server service, concatenate a URL as https://base_url/proxy/7756/
  5. when the code-server login page occurs, skip input the xxx into the password area. F12 edit the application cookie, set key=code-server-session, value="$argon2i$v=19$m=4096,t=3,p=1$xxx$xxx", refresh the browser

Expected

Failed to login into the code-server. The hashed-password in the config.yaml should not be the plain credentials

Actual

successfully login into the code-server

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingsecuritySecurity relatedtriageThis issue needs to be triaged by a maintainer

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions


      Back | FazBrowse Home | New Git URL