T05 · Unauthorized Access and Privilege Escalation
- Location
skills/smyx_common/scripts/util.py:542- Finding
Caller-Controlled Identity Enables Unauthorized Account Impersonation
- Content
View full analysis
Vulnerability Details
File Location:
scripts/smyx_plant_vitality_index_analysis.py:45, 60-65;skills/smyx_common/scripts/util.py:458-471, 542-612
Vulnerability Type: Improper authentication and caller-controlled identity impersonation
Risk Level: HighTechnical Analysis
The CLI accepts an unrestricted hidden
--open-idargument and treats it as a trusted internal identity:python parser.add_argument("--open-id", required=False, help=argparse.SUPPRESS)The supplied value is passed directly into identity initialization:
python OpenIdUtil.resolve_current_open_id(args.open_id, use_current=bool(args.open_id)) if args.list: open_id = ConstantEnum.CURRENT__OPEN_ID result = show_analyze_list(open_id) print(result) exit(0)resolve_current_open_idperforms no authentication or integrity verification before installing that value as the process-wide current identity:python @classmethod def resolve_current_open_id(cls, open_id=None, use_current=True): """解析并初始化当前 open-id,返回最终使用值。""" resolved_open_id = (open_id or "").strip() if isinstance(open_id, str) else open_id if not resolved_open_id and use_current: resolved_open_id = ConstantEnum.CURRENT__OPEN_ID or ConstantEnum.CURRENT__USER_NAME if not resolved_open_id: resolved_open_id = cls.get_api_key_file_open_id() if not resolved_open_id: resolved_open_id = cls.get_or_create_default_open_id() ConstantEnum.CURRENT__OPEN_ID = resolved_open_id if not ConstantEnum.CURRENT__USER_NAME: ConstantEnum.CURRENT__USER_NAME = resolved_open_id return resolved_open_idThe request layer subsequently uses that identity to perform a silent login. It sends the same caller-controlled value as both the Open ID and mobile identifier, without presenting an existing user credential or a cryptographically verified assertion:
python def _get_or_create_user(username): _url = ApiEnum.BASE_URL_HEALTH + "/sys/ph ...[truncated 4006 chars]- Remediation
View remediation
Remediation Suggestions
- Remove caller-controlled identity selection from the public CLI. Do not accept
--open-idas a direct authentication mechanism. - Obtain identities only from a trusted, authenticated upstream context and verify the integrity and issuer of that context before use.
- Replace identifier-only silent login with a standard authenticated exchange, such as OAuth, a signed short-lived assertion, or a session token bound to the verified user.
- Require the server to reject
/sys/phoneLoginrequests that provide only anopenIdor mobile value without proof of ownership. - Enforce report ownership and tenant authorization server-side for every list, detail, export, and analysis endpoint; do not rely solely on client-supplied
pnaUserName. - Bind issued tokens to the verified identity, intended client, tenant, and minimum required scopes.
- Avoid persisting returned tokens in plaintext where possible. Use an operating-system credential store or encrypted storage with restrictive file permissions.
- Add negative authorization tests confirming that one caller cannot select another user's identifier and retrieve that user's reports.
- Remove caller-controlled identity selection from the public CLI. Do not accept
