Originally created by: pyy3
Severity: High · Type: security
docker-compose.yml ships weak, well-known default credentials via :- fallbacks. A docker compose up without a generated .env deploys the stack with these defaults.
docker-compose.yml:
ADMIN_PASSWORD: ${ADMIN_PASSWORD:-admin123}
DB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD:-rootpassword}
CLICKHOUSE_PASSWORD: ${CLICKHOUSE_PASSWORD:-open_epm_dev}
.env.example mirrors the same values.
CUBEJS_API_SECRET is handled correctly — it is required, not defaulted:
CUBEJS_API_SECRET: ${CUBEJS_API_SECRET:?Run ./deploy.sh to generate CUBEJS_API_SECRET}
Any deployment that skips deploy.sh / .env generation comes up with admin123 / rootpassword / open_epm_dev — trivial full-stack compromise (Frappe admin, MariaDB root, ClickHouse).
Apply the same :? required-variable pattern to the three password vars so the stack refuses to start without explicit secrets:
ADMIN_PASSWORD: ${ADMIN_PASSWORD:?run ./deploy.sh to generate}
DB_ROOT_PASSWORD: ${DB_ROOT_PASSWORD:?run ./deploy.sh to generate}
CLICKHOUSE_PASSWORD: ${CLICKHOUSE_PASSWORD:?run ./deploy.sh to generate}
Also avoid printing generated credentials to the console in deploy.sh.
Originally posted by: pyy3
Fixed in [#34] (merged to
main).Related
Tickets:
#34Ticket changed by: pyy3