T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/passmanager.py:257- Finding
Declared RBAC Is Not Enforced on Credential and Administrative Operations
- Content
View full analysis
bool: """检查用户是否有权限执行某操作""" if not user: return False conn = sqlite3.connect(self.db_path) c = conn.cursor() c.execute("SELECT role FROM team_members WHERE name = ?", (user,)) row = c.fetchone() conn.close() if not row: return False role = row[0] role_perms = { "admin": ["add", "get", "list", "update", "delete", "backup", "restore", "audit", "team_add", "team_remove", "team_list", "status", "init"], "user": ["add", "get", "list", "update"], "auditor": ["get", "list", "audit"], "guest": ["get"], } allowed = role_perms.get(role, []) return required_action in allowed ``` For example, privileged CLI handlers invoke the underlying operations directly, without calling `check_permission()` or authenticating the claimed administrator: ```python def cmd_delete(args): pm = PassManager() ok = pm.delete(args.user, args.type, args.service, args.username) if ok: print(f"✅ 凭证已删除: {args.type}/{args.service}/{args.username}") else: print("❌ 删除失败。凭证不存在。") ``` ```python def cmd_restore(args): pm = PassManager() if pm.restore(args.input): print(f"✅ 恢复成功: {args.input}") else: print("❌ 恢复失败。检查备份文件是否存在。") ``` ```python def cmd_team_add(args): pm = PassManager() if pm.team_add(args.admin, args.name, args.role): print(f"✅ 团队成员添加成功: {args.name} ({args.role})") else: print("❌ 添加失败。用户可能已存在。") ``` ### Technical Analysis The RBA ...[truncated 2602 chars]- Remediation
View remediation
