Closed Bug 1794420 Opened 3 years ago Closed 3 years ago

Taskcluster Credentials Leaked

Categories

(Taskcluster :: General, task)

Tracking

(Not tracked)

RESOLVED FIXED

People

(Reporter: griffin.francis.1993, Unassigned)

Details

(Keywords: reporter-external, sec-high, wsec-disclosure, Whiteboard: [reporter-external] [web-bounty-form] [verif?])

Hi All,

I have been sitting on these credentials for around 6+ months now, apologies about that. They were leaked in some logs on the community taskcluster instance. I can no longer remember the location of these logs as it was so long ago. However I have attached the credentials below so they can be rotated.

https://community-tc.services.mozilla.com/

client_id: project/taskcluster/docker-worker/ci
access_token: 09L114gfTxqV7RHHCkA3oAvG5Fofb7Rz-ZV1Vqfwkeew

Permissions -

Signed In As
project/taskcluster/docker-worker/ci

Certificate
n/a

Client ID
project/taskcluster/docker-worker/ci

Expires
in 1000 years

Scopes
assume:anonymous

assume:project:taskcluster:docker-worker-tester

assume:project:taskcluster:worker-test-scopes

assume:worker-id:docker-worker/docker-worker

assume:worker-id:random-local-worker/docker-worker

auth:current-scopes

auth:expand-scopes

auth:get-client:*

auth:get-role:*

auth:list-clients

auth:list-roles

aws-provisioner:create-secret:*

docker-worker:cache:docker-worker-garbage-*

docker-worker:capability:device:hostSharedMemory

docker-worker:capability:device:hostSharedMemory:null-provisioner/*

docker-worker:capability:device:loopbackAudio

docker-worker:capability:device:loopbackAudio:null-provisioner/*

docker-worker:capability:device:loopbackVideo

docker-worker:capability:device:loopbackVideo:null-provisioner/*

docker-worker:capability:disableSeccomp

docker-worker:capability:disableSeccomp:null-provisioner/*

docker-worker:capability:privileged

docker-worker:capability:privileged:null-provisioner/*

docker-worker:image:localhost:*

github:get-badge:*

github:get-repository:*

github:latest-status:*

github:list-builds

hooks:get:*

hooks:list-hooks:*

hooks:list-last-fires:*

hooks:status:*

index:find-task:*

index:list-namespaces:*

index:list-tasks:*

purge-cache:all-purge-requests

purge-cache:null-provisioner/*

purge-cache:purge-requests:*

queue:cancel-task

queue:cancel-task:docker-worker-tests/*

queue:claim-task

queue:claim-task:null-provisioner/*

queue:claim-work:null-provisioner/*

queue:create-artifact:*

queue:create-task:lowest:null-provisioner/*

queue:create-task:lowest:proj-taskcluster/ci

queue:create-task:project:none

queue:get-artifact:private/docker-worker-tests/*

queue:get-artifact:public/*

queue:get-provisioner:*

queue:get-task:*

queue:get-worker-type:*

queue:get-worker:*

queue:list-artifacts:*

queue:list-dependent-tasks:*

queue:list-provisioners

queue:list-task-group:*

queue:list-worker-types:*

queue:list-workers:*

queue:pending-count:*

queue:rerun-task:taskcluster-level-1/*

queue:resolve-task

queue:route:statuses

queue:scheduler-id:docker-worker-tests

queue:scheduler-id:taskcluster-github

queue:status:*

queue:worker-id:docker-worker/docker-worker

queue:worker-id:random-local-worker/docker-worker

queue:worker-id:random-local-worker/dummy-worker-*

secrets:get:project/taskcluster/taskcluster-worker/stateless-dns

secrets:get:project/taskcluster/testing/docker-worker/ci-creds

secrets:get:project/taskcluster/testing/docker-worker/pulse-creds

secrets:list-secrets

worker-manager:get-worker-pool:*

worker-manager:get-worker:*

worker-manager:list-providers

worker-manager:list-worker-pool-errors:*

worker-manager:list-worker-pools

worker-manager:list-workers:*

Flags: sec-bounty?
Group: websites-security → taskcluster-security
Component: Other → General
Product: Websites → Taskcluster

Hello Aki,

Can you please take a look? We are also wondering what privileges the scope docker-worker:capability:privileged provides.

Thanks,
Frida

Flags: needinfo?(aki)

Hi Frida,
This is for the community cluster, which Releng doesn't do anything with. From the perspective of Mozilla release pipelines, there is no direct risk, though some developers may be running tasks in the Community cluster, then taking the artifacts from those tasks and landing them in-tree. (If this is a concern, we may want to move such tasks to the FirefoxCI cluster.)

Also CCing :ahal and :jlorenzo, since I will be leaving Mozilla at EOY.

Pete, Yarik, Matt, any thoughts on the Community cluster?

Flags: needinfo?(ykurmyza)
Flags: needinfo?(pmoore)
Flags: needinfo?(mboris)
Flags: needinfo?(aki)

Hi Griffin,

Thanks for flagging. The Taskcluster engineering team will look into this and will rotate that access key. It would help us tremendously if you were able to find the log that had this leak, or more information as to how you stumbled upon it in the first place.

You can read up on the docker-worker:capability:privileged scope here.

Status: UNCONFIRMED → NEW
Ever confirmed: true

Hi, we already rotated access tokens yesterday.
Also checked logs to make sure that those credentials were not used for any unusual calls and if there would be any failed authentication attempts after the rotation. Nothing suspicious detected from our side.

I think we can close this.
Thanks for reporting.

upd: is it fine to close this issue, or there should be any other actions on this?

Status: NEW → RESOLVED
Closed: 3 years ago
Flags: needinfo?(ykurmyza)
Resolution: --- → FIXED
Flags: needinfo?(mboris)

Thanks for rotating the credentials. The log file was initially found within Slack because the developers were complaining about the credentials being leaked, however never rotated them. I tried to go back and find their messages however they had either been removed or deleted.

Flags: needinfo?(pmoore)
Flags: sec-bounty? → sec-bounty+

The ability to compromise community artifacts could be a serious impact to a small number of users, so makes the cut for a "sec-high". Although the bug bounty doesn't cover community "web sites", the community taskcluster is on the Core Sites list. Awarding a bounty

Group: taskcluster-security
You need to log in before you can comment on or make changes to this bug.