Taskcluster Credentials Leaked
Categories
(Taskcluster :: General, task)
Tracking
(Not tracked)
People
(Reporter: griffin.francis.1993, Unassigned)
Details
(Keywords: reporter-external, sec-high, wsec-disclosure, Whiteboard: [reporter-external] [web-bounty-form] [verif?])
Hi All,
I have been sitting on these credentials for around 6+ months now, apologies about that. They were leaked in some logs on the community taskcluster instance. I can no longer remember the location of these logs as it was so long ago. However I have attached the credentials below so they can be rotated.
https://community-tc.services.mozilla.com/
client_id: project/taskcluster/docker-worker/ci
access_token: 09L114gfTxqV7RHHCkA3oAvG5Fofb7Rz-ZV1Vqfwkeew
Permissions -
Signed In As
project/taskcluster/docker-worker/ci
Certificate
n/a
Client ID
project/taskcluster/docker-worker/ci
Expires
in 1000 years
Scopes
assume:anonymous
assume:project:taskcluster:docker-worker-tester
assume:project:taskcluster:worker-test-scopes
assume:worker-id:docker-worker/docker-worker
assume:worker-id:random-local-worker/docker-worker
auth:current-scopes
auth:expand-scopes
auth:get-client:*
auth:get-role:*
auth:list-clients
auth:list-roles
aws-provisioner:create-secret:*
docker-worker:cache:docker-worker-garbage-*
docker-worker:capability:device:hostSharedMemory
docker-worker:capability:device:hostSharedMemory:null-provisioner/*
docker-worker:capability:device:loopbackAudio
docker-worker:capability:device:loopbackAudio:null-provisioner/*
docker-worker:capability:device:loopbackVideo
docker-worker:capability:device:loopbackVideo:null-provisioner/*
docker-worker:capability:disableSeccomp
docker-worker:capability:disableSeccomp:null-provisioner/*
docker-worker:capability:privileged
docker-worker:capability:privileged:null-provisioner/*
docker-worker:image:localhost:*
github:get-badge:*
github:get-repository:*
github:latest-status:*
github:list-builds
hooks:get:*
hooks:list-hooks:*
hooks:list-last-fires:*
hooks:status:*
index:find-task:*
index:list-namespaces:*
index:list-tasks:*
purge-cache:all-purge-requests
purge-cache:null-provisioner/*
purge-cache:purge-requests:*
queue:cancel-task
queue:cancel-task:docker-worker-tests/*
queue:claim-task
queue:claim-task:null-provisioner/*
queue:claim-work:null-provisioner/*
queue:create-artifact:*
queue:create-task:lowest:null-provisioner/*
queue:create-task:lowest:proj-taskcluster/ci
queue:create-task:project:none
queue:get-artifact:private/docker-worker-tests/*
queue:get-artifact:public/*
queue:get-provisioner:*
queue:get-task:*
queue:get-worker-type:*
queue:get-worker:*
queue:list-artifacts:*
queue:list-dependent-tasks:*
queue:list-provisioners
queue:list-task-group:*
queue:list-worker-types:*
queue:list-workers:*
queue:pending-count:*
queue:rerun-task:taskcluster-level-1/*
queue:resolve-task
queue:route:statuses
queue:scheduler-id:docker-worker-tests
queue:scheduler-id:taskcluster-github
queue:status:*
queue:worker-id:docker-worker/docker-worker
queue:worker-id:random-local-worker/docker-worker
queue:worker-id:random-local-worker/dummy-worker-*
secrets:get:project/taskcluster/taskcluster-worker/stateless-dns
secrets:get:project/taskcluster/testing/docker-worker/ci-creds
secrets:get:project/taskcluster/testing/docker-worker/pulse-creds
secrets:list-secrets
worker-manager:get-worker-pool:*
worker-manager:get-worker:*
worker-manager:list-providers
worker-manager:list-worker-pool-errors:*
worker-manager:list-worker-pools
worker-manager:list-workers:*
Updated•3 years ago
|
Comment 1•3 years ago
|
||
Hello Aki,
Can you please take a look? We are also wondering what privileges the scope docker-worker:capability:privileged provides.
Thanks,
Frida
Comment 2•3 years ago
•
|
||
Hi Frida,
This is for the community cluster, which Releng doesn't do anything with. From the perspective of Mozilla release pipelines, there is no direct risk, though some developers may be running tasks in the Community cluster, then taking the artifacts from those tasks and landing them in-tree. (If this is a concern, we may want to move such tasks to the FirefoxCI cluster.)
Also CCing :ahal and :jlorenzo, since I will be leaving Mozilla at EOY.
Pete, Yarik, Matt, any thoughts on the Community cluster?
Comment 3•3 years ago
•
|
||
Hi Griffin,
Thanks for flagging. The Taskcluster engineering team will look into this and will rotate that access key. It would help us tremendously if you were able to find the log that had this leak, or more information as to how you stumbled upon it in the first place.
You can read up on the docker-worker:capability:privileged scope here.
Updated•3 years ago
|
Comment 4•3 years ago
•
|
||
Hi, we already rotated access tokens yesterday.
Also checked logs to make sure that those credentials were not used for any unusual calls and if there would be any failed authentication attempts after the rotation. Nothing suspicious detected from our side.
I think we can close this.
Thanks for reporting.
upd: is it fine to close this issue, or there should be any other actions on this?
Updated•3 years ago
|
| Reporter | ||
Comment 5•3 years ago
|
||
Thanks for rotating the credentials. The log file was initially found within Slack because the developers were complaining about the credentials being leaked, however never rotated them. I tried to go back and find their messages however they had either been removed or deleted.
Updated•3 years ago
|
Updated•3 years ago
|
Comment 6•3 years ago
|
||
The ability to compromise community artifacts could be a serious impact to a small number of users, so makes the cut for a "sec-high". Although the bug bounty doesn't cover community "web sites", the community taskcluster is on the Core Sites list. Awarding a bounty
Updated•3 years ago
|
Updated•2 years ago
|
Description
•