T09 · Insecure Skill Coding Practices
- Location
SKILL.md:281- Finding
Weak Hardcoded Database Credential with Broad Host Port Exposure
- Content
View full analysis
Vulnerability Details
File Location:
SKILL.md, lines 281–289
Vulnerability Type: Hardcoded weak credential and insecure network exposure
Risk Level: Mediumbash **Database container:** ```bash docker run -d \ --name postgres \ -e POSTGRES_PASSWORD=secret \ -e POSTGRES_DB=mydb \ -v postgres-data:/var/lib/postgresql/data \ -p 5432:5432 \ postgres:15text ### Technical Analysis The documented Docker workflow configures PostgreSQL with the predictable plaintext password `secret`. Supplying the password through `-e` also places it in the container configuration, where users with sufficient Docker access can retrieve it through container inspection. The mapping `-p 5432:5432` publishes the database port on all host interfaces by default. If network firewalls or host access controls do not block the port, the database can become reachable from untrusted networks. Combining a predictable credential with broad network publication creates a directly exploitable authentication weakness for users who copy the example without hardening it. ### Attack Path 1. A user copies the documented command and starts the PostgreSQL container. 2. Docker publishes TCP port 5432 on all host interfaces. 3. An attacker identifies the exposed PostgreSQL service from a reachable network. 4. The attacker attempts authentication using the documented password `secret` and an applicable database role, such as the image's default administrative role. 5. If authentication succeeds, the attacker accesses the configured database with that role's privileges. Exploitation requires network reachability and knowledge or discovery of a valid database username. ### Impact Assessment A successful attacker could obtain the privileges granted to the compromised PostgreSQL role. If the default administrative role is compromised, this may permit reading, modifying, or deleting databases and database objects managed ...[truncated 174 chars]- Remediation
View remediation
Remediation Suggestions
- Replace the fixed password with a strong, randomly generated secret.
- Avoid placing production credentials directly in reusable commands or committed documentation. Supply them through a protected secret file or an orchestrator-supported secrets mechanism.
- Restrict publication to the loopback interface when only local access is required:
bash -p 127.0.0.1:5432:5432 - Omit the published port entirely when only containers on a private Docker network need database access.
- Add explicit guidance concerning firewall rules, trusted-source allowlists, TLS, least-privilege database roles, and credential rotation.
- Clearly label demonstration values as placeholders that must not be used in production.
