Docker image writes database and admin passwords to the container logs
Affected versions
- Kimai versions >= 2.58.0 are affected by this security issue
- The issue has been fixed in Kimai 2.67.0
- Severity: Medium
- A CVE ID is requested, pending assignment
Description
The official Kimai Docker image wrote the database password and the initial admin password into the container logs every time the container started. Anyone who can read these logs, but should not have access to Kimai itself, could use them to log in as administrator or access the database directly.
- The startup script ran with command tracing turned on, which prints every command, including its arguments, to the container output.
- This exposed the database credentials (from
DATABASE_URL) on every start. - If
ADMINPASSandADMINMAILwere set, the admin password was also printed on every start, not only on the first one. - If you used one of these variables with an affected image, your logs may still contain the credentials. Change the database password and the admin password, and remove or restrict access to old container logs.
- People with access to these container logs (for example via
docker logs, a log aggregator, or a monitoring tool) could obtain the credentials.
Only installations using the official Kimai Docker image are affected. Kimai Cloud and OnPremise installations without Docker are not affected.
Solution
Kimai 2.67 turned off command tracing by default and passes the database credentials to the connection check as environment variables, so they no longer appear in logs or the process list. Kimai 2.68 removes command tracing from the startup script entirely, including the optional debug mode.
- Users should delete their old docker logs after the update.
- Users should change the database password and the admin password
Users should update to 2.67.0 or newer.
Credits
- Reported by: Xylakant
- Patched by: kevinpapst
Kimai