This commit addresses multiple CRITICAL, HIGH, and MEDIUM severity security vulnerabilities identified in the security audit: CRITICAL FIXES: - Fix weak RNG for recovery codes - replaced Enum.random() with :crypto.strong_rand_bytes/1 for cryptographically secure token generation - Fix subscription limit race conditions - moved free org and device quota checks inside transactions with FOR UPDATE locks to prevent concurrent bypass - Fix default organization race condition - moved is_default check inside transaction to prevent multiple defaults per user HIGH SEVERITY FIXES: - Fix agent token deletion race condition - moved PubSub broadcast inside transaction to ensure agents only receive notification after successful deletion MEDIUM SEVERITY FIXES: - Fix LIKE wildcard injection in search - applied sanitize_like() to all user-facing search queries in devices.ex, sites.ex, and gaiia.ex to prevent enumeration attacks - Fix Jason.decode! DoS - replaced with safe Jason.decode/1 with error handling in device_live/index.ex - Fix SSRF vulnerability - added URL validation in HTTP executor to block requests to private/internal IP ranges (127.0.0.0/8, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16, 169.254.0.0/16) - Fix error information leakage - replaced inspect() in API responses with generic error messages, logging details server-side only - Fix atom table pollution - HTTP method normalization now uses whitelist mapping instead of String.to_atom() SECURITY IMPROVEMENTS: - All quota checks now use pessimistic locking (SELECT FOR UPDATE) to prevent TOCTOU race conditions - Private IP validation prevents cloud metadata service access (169.254.169.254) - DNS resolution performed before HTTP requests to detect IP spoofing - Error details logged server-side but not exposed to clients Files changed: - lib/towerops/accounts/user_recovery_code.ex - lib/towerops/organizations.ex - lib/towerops/devices.ex - lib/towerops/sites.ex - lib/towerops/gaiia.ex - lib/towerops/agents.ex - lib/towerops/monitoring/executors/http_executor.ex - lib/towerops_web/live/device_live/index.ex - lib/towerops_web/controllers/api/v1/mib_controller.ex - lib/towerops_web/controllers/api/v1/agent_release_webhook_controller.ex - lib/towerops_web/controllers/api/v1/geoip_controller.ex Reviewed-on: graham/towerops-web#108 |
||
|---|---|---|
| .. | ||
| browser_session.ex | ||
| hibp.ex | ||
| login_attempt.ex | ||
| policy_version.ex | ||
| scope.ex | ||
| user.ex | ||
| user_consent.ex | ||
| user_notifier.ex | ||
| user_recovery_code.ex | ||
| user_token.ex | ||
| user_totp_device.ex | ||