T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/lib.py:464- Finding
Channel configuration silently enables unrestricted bot and gateway access
- Content
View full analysis
Vulnerability Details
File Location:
scripts/lib.py:464-474
Vulnerability Type: Access-control weakening through permissive defaults
Risk Level: HighVulnerable code:
bash if [ "$BOT_PLATFORM" = "feishu" ]; then echo "Configuring Feishu channel..." set_env_variable "$ENV_PATH" "FEISHU_APP_ID" "$FEISHU_APP_ID" set_env_variable "$ENV_PATH" "FEISHU_APP_SECRET" "$FEISHU_APP_SECRET" set_env_variable "$ENV_PATH" "FEISHU_DOMAIN" "feishu" set_env_variable "$ENV_PATH" "FEISHU_CONNECTION_MODE" "websocket" set_env_variable "$ENV_PATH" "FEISHU_ALLOW_ALL_USERS" "true" set_env_variable "$ENV_PATH" "FEISHU_ALLOWED_USERS" "" set_env_variable "$ENV_PATH" "FEISHU_GROUP_POLICY" "open" set_env_variable "$ENV_PATH" "GATEWAY_ALLOW_ALL_USERS" "true" echo "✅ Feishu configuration written successfully" elif [ "$BOT_PLATFORM" = "wecom" ]; then echo "Configuring WeCom channel..." set_env_variable "$ENV_PATH" "WECOM_BOT_ID" "$WECOM_BOT_ID" set_env_variable "$ENV_PATH" "WECOM_SECRET" "$WECOM_SECRET" set_env_variable "$ENV_PATH" "GATEWAY_ALLOW_ALL_USERS" "true" echo "✅ WeCom configuration written successfully" fiTechnical Analysis
The channel-installation template does more than install the credentials selected by the administrator. For Feishu, it explicitly enables all users, clears the user allowlist, opens the group policy, and enables unrestricted gateway access. For WeCom, it also enables unrestricted gateway access.
The remote configuration script is selected and populated by
install_channel_remoteinscripts/lib.py:664-705. The normal channel workflow invokes that function fromscripts/channels.py:141-145, causing Huawei Cloud COC to execute the generated script on the selected Hermes instance. The script normally executes with root privileges because the documented and implemented default execution user isroot.Interactive ...[truncated 2184 chars]
- Remediation
View remediation
Remediation Suggestions
- Default
FEISHU_ALLOW_ALL_USERSandGATEWAY_ALLOW_ALL_USERStofalse. - Require explicit administrator-provided user and group allowlists before enabling the channel.
- Do not clear
FEISHU_ALLOWED_USERSor overwrite existing access-control settings unless the administrator explicitly requests replacement. - Expose public access as a clearly named opt-in option, such as
--allow-all-users, rather than enabling it as an undocumented side effect. - Display the resulting authorization policy before execution and require explicit confirmation when public access is requested. Require the same explicit authorization in non-interactive mode through a dedicated flag.
- Validate that an allowlist is non-empty whenever unrestricted access is disabled.
- Apply least-privilege execution where possible and restrict the COC script to modifying only the necessary channel settings.
- Add automated tests asserting that channel setup preserves restrictive access-control defaults unless an explicit public-access option is supplied.
- Default
