T05 · Unauthorized Access and Privilege Escalation
- Location
scripts/install.sh:26- Finding
Overbroad Passwordless Sudo Authorization for the Dashboard Account
- Content
View full analysis
"$SUDOERS_FILE" << 'SUDOEOF' # Allow openclaw-dashboard to check security status without password Cmnd_Alias DASHBOARD_CMDS = /usr/bin/systemctl is-active *, \ /usr/bin/systemctl status *, \ /usr/bin/fail2ban-client status *, \ /usr/sbin/ufw status, \ /usr/bin/firewall-cmd --state, \ /usr/bin/journalctl *, \ /usr/bin/ss *, \ /usr/bin/tailscale status * openclaw-dashboard ALL=(ALL) NOPASSWD: DASHBOARD_CMDS SUDOEOF chmod 440 "$SUDOERS_FILE" ``` ### Technical Analysis The installer creates a passwordless sudo policy for the `openclaw-dashboard` account. Several permitted commands accept unrestricted wildcard arguments, including: - `/usr/bin/journalctl *` - `/usr/bin/systemctl status *` - `/usr/bin/fail2ban-client status *` - `/usr/bin/ss *` The rule also permits execution as any target account through `ALL=(ALL)`, even though the dashboard only needs narrowly scoped, read-only checks as root. An attacker who obtains command execution as this account could supply arguments that were not anticipated by the application. In particular, unrestricted privileged journal access can expose logs from arbitrary services. Such logs may contain environment details, usernames, internal addresses, command lines, request data, tokens accidentally logged by other applications, or other operationally sensitive information. Several grants are broader than the commands actually invoked with `sudo` in `server.js`. The implementation uses sudo for specific `ss`, `ufw`, `firewall-cmd`, ` ...[truncated 1788 chars]- Remediation
View remediation
