Central Dogma Maven Package: Hard-coded Secret Risk
- Severity
- HIGH
- Affected component
- com.linecorp.centraldogma:centraldogma-server (maven)
- Affected versions
- < 0.64.1 or >= 0.17.0, <= 0.17.0 or >= 0.18.0, <= 0.18.0 or >= 0.19.0, <= 0.19.0 or >= 0.20.0, <= 0.20.0 or >= 0.20.1, <= 0.20.1 or >= 0.21.0, <= 0.21.0 or >= 0.21.1, <= 0.21.1 or >= 0.22.0, <= 0.22.0 or >= 0.23.0, <= 0.23.0 or >= 0.24.0, <= 0.24.0 or >= 0.25.0, <= 0.25.0 or >= 0.26.0, <= 0.26.0 or >= 0.27.0, <= 0.27.0 or >= 0.28.0, <= 0.28.0 or >= 0.28.1, <= 0.28.1 or >= 0.29.0, <= 0.29.0 or >= 0.30.0, <= 0.30.0 or >= 0.31.0, <= 0.31.0 or >= 0.32.0, <= 0.32.0 or >= 0.32.1, <= 0.32.1 or >= 0.33.0, <= 0.33.0 or >= 0.34.0, <= 0.34.0 or >= 0.35.0, <= 0.35.0 or >= 0.35.1, <= 0.35.1 or >= 0.36.0, <= 0.36.0 or >= 0.37.0, <= 0.37.0 or >= 0.38.0, <= 0.38.0 or >= 0.39.0, <= 0.39.0 or >= 0.39.1, <= 0.39.1 or >= 0.39.2, <= 0.39.2 or >= 0.40.0, <= 0.40.0 or >= 0.40.1, <= 0.40.1 or >= 0.41.0, <= 0.41.0 or >= 0.41.1, <= 0.41.1 or >= 0.41.2, <= 0.41.2 or >= 0.41.3, <= 0.41.3 or >= 0.41.4, <= 0.41.4 or >= 0.42.0, <= 0.42.0 or >= 0.43.0, <= 0.43.0 or >= 0.43.1, <= 0.43.1 or >= 0.43.2, <= 0.43.2 or >= 0.43.3, <= 0.43.3 or >= 0.43.4, <= 0.43.4 or >= 0.44.0, <= 0.44.0 or >= 0.44.1, <= 0.44.1 or >= 0.44.10, <= 0.44.10 or >= 0.44.11, <= 0.44.11 or >= 0.44.12, <= 0.44.12 or >= 0.44.13, <= 0.44.13 or >= 0.44.14, <= 0.44.14 or >= 0.44.2, <= 0.44.2 or >= 0.44.3, <= 0.44.3 or >= 0.44.4, <= 0.44.4 or >= 0.44.5, <= 0.44.5 or >= 0.44.6, <= 0.44.6 or >= 0.44.7, <= 0.44.7 or >= 0.44.8, <= 0.44.8 or >= 0.44.9, <= 0.44.9 or >= 0.45.0, <= 0.45.0 or >= 0.45.1, <= 0.45.1 or >= 0.46.0, <= 0.46.0 or >= 0.46.1, <= 0.46.1 or >= 0.47.0, <= 0.47.0 or >= 0.47.1, <= 0.47.1 or >= 0.48.0, <= 0.48.0 or >= 0.49.0, <= 0.49.0 or >= 0.49.1, <= 0.49.1 or >= 0.50.0, <= 0.50.0 or >= 0.51.0, <= 0.51.0 or >= 0.51.1, <= 0.51.1 or >= 0.52.0, <= 0.52.0 or >= 0.52.1, <= 0.52.1 or >= 0.52.2, <= 0.52.2 or >= 0.52.3, <= 0.52.3 or >= 0.52.4, <= 0.52.4 or >= 0.52.5, <= 0.52.5 or >= 0.52.6, <= 0.52.6 or >= 0.53.0, <= 0.53.0 or >= 0.53.1, <= 0.53.1 or >= 0.54.0, <= 0.54.0 or >= 0.55.0, <= 0.55.0 or >= 0.55.1, <= 0.55.1 or >= 0.55.2, <= 0.55.2 or >= 0.56.0, <= 0.56.0 or >= 0.56.1, <= 0.56.1 or >= 0.56.2, <= 0.56.2 or >= 0.57.0, <= 0.57.0 or >= 0.57.1, <= 0.57.1 or >= 0.57.2, <= 0.57.2 or >= 0.57.3, <= 0.57.3 or >= 0.58.0, <= 0.58.0 or >= 0.58.1, <= 0.58.1 or >= 0.59.0, <= 0.59.0 or >= 0.60.0, <= 0.60.0 or >= 0.60.1, <= 0.60.1 or >= 0.61.0, <= 0.61.0 or >= 0.61.1, <= 0.61.1 or >= 0.61.2, <= 0.61.2 or >= 0.61.3, <= 0.61.3 or >= 0.61.4, <= 0.61.4 or >= 0.61.5, <= 0.61.5 or >= 0.62.0, <= 0.62.0 or >= 0.62.1, <= 0.62.1 or >= 0.63.0, <= 0.63.0 or >= 0.63.1, <= 0.63.1 or >= 0.63.2, <= 0.63.2 or >= 0.63.3, <= 0.63.3 or >= 0.64.0, <= 0.64.0
- Patched version
- Not yet available
An early warning has been issued regarding a hard-coded replication secret in the Central Dogma Maven package, which could potentially enable a cluster takeover if leaked.
What happened
The Central Dogma Maven package reportedly contains a hard-coded replication secret, which is a critical security risk. This secret, if leaked, could enable unauthorized access and takeover of a cluster. The issue has been tracked under the ID GHSA-2J95-GQXF-V3VG and is classified as a high severity threat. It is under investigation and has not been exploited in the wild as of the latest reports.
The affected component is com.linecorp.centraldogma:centraldogma-server (maven), with a complex version range that includes many versions. The primary sources indicate that the secret is hard-coded as 'ch4n63m3' and has a silent fallback mechanism that exacerbates the risk.
What to do about it
- Review your Central Dogma configurations to identify if the hard-coded replication secret is in use.
- Update the replication secret in Central Dogma configurations to a secure, unique value.
- Monitor the primary sources for updates on the issue and any official fixes that may be released.
- Consider implementing additional security measures to protect against potential cluster takeovers.
How 0Day would have caught this
com.linecorp.centraldogma:centraldogma-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You may be affected if you are using com.linecorp.centraldogma:centraldogma-server (maven) in the specified version range. Consult the primary sources for the exact versions.
What should I do right now?
Immediately review and update the replication secret in your Central Dogma configurations to a secure value.
Is there an official fix available?
No official fix has been published yet. Monitor the primary sources for updates.