Page MenuHomeVyOS Platform

remote.py CurlC.upload() leaks URL credentials to stdout via leftover debug print
Open, NormalPublic

Description

Component: python/vyos/remote.py

Finding (automated security review, MEDIUM): In the CurlC uploader, upload() runs:

print(f'{self.command} "{self.urlstring}"')

self.urlstring is the full urllib.parse.urlunsplit(url) and may contain userinfo (scheme://user:password@host/...). Printing it to stdout exposes embedded credentials in op-mode output and any captured logs.

Confirmation it is leftover debug: This is the only such print(self.command/urlstring) in the file. The sibling CurlC.download() performs the equivalent operation without the print, so the line is not needed for functionality.

Proposed fix (see PR): Remove the print(...) line. (If diagnostic output is ever wanted, redact userinfo first via urlsplit → strip netloc before @ → urlunsplit.)

Surfaced by automated security review on the rolling branch. The flagged code is already public in vyos/vyos-1x.

Details

Version
rolling
Issue type
Bug (incorrect behavior)

Event Timeline

syncer triaged this task as Normal priority.