{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/central-dogma/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Central Dogma"],"_cs_severities":["high"],"_cs_tags":["configuration-vulnerability","hardcoded-credential","central-dogma","zookeeper"],"_cs_type":"advisory","_cs_vendors":["LINE"],"content_html":"\u003cp\u003eCentral Dogma clusters, when configured for high availability using ZooKeeper replication, are vulnerable to unauthorized access due to a hard-coded default secret. The \u003ccode\u003eZooKeeperReplicationConfig.secret()\u003c/code\u003e method silently defaults to the string \u0026quot;ch4n63m3\u0026quot; if no \u003ccode\u003ereplication.secret\u003c/code\u003e is provided in the configuration. This secret is used for SASL authentication across both the local client-facing ZooKeeper port and the inter-replica quorum ports. Because the default value is publicly visible in the open-source repository and no warning is issued when it is utilized, production clusters are susceptible to compromise if they rely on default configurations. An attacker with network reachability to the ZooKeeper ports can authenticate as the 'super' user, enabling full read/write access to the internal replication logs that govern the entire Central Dogma cluster.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a Central Dogma cluster with high-availability replication enabled but without a customized \u003ccode\u003ereplication.secret\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker establishes network connectivity to a ZooKeeper quorum port (exposed on the inter-replica network) or utilizes local access to reach the loopback-bound client port.\u003c/li\u003e\n\u003cli\u003eAttacker initiates a SASL DIGEST-MD5 handshake using the username 'super' and the publicly known default secret 'ch4n63m3'.\u003c/li\u003e\n\u003cli\u003eAuthentication succeeds, allowing the attacker to join the ZK ensemble as a learner or authenticate as a super-user client.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates existing configuration logs via the ZK znodes \u003ccode\u003e/dogma/logs\u003c/code\u003e and \u003ccode\u003e/dogma/log_blocks\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eAttacker monitors replication in real-time to intercept sensitive configuration secrets or session master keys.\u003c/li\u003e\n\u003cli\u003eAttacker optionally injects forged \u003ccode\u003eReplicationLog\u003c/code\u003e entries to be replayed by legitimate replicas, leading to unauthorized command execution such as \u003ccode\u003ePURGE_PROJECT\u003c/code\u003e or \u003ccode\u003eROTATE_SESSION_MASTER_KEY\u003c/code\u003e across all cluster nodes.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a complete cluster takeover. An attacker can read the entire history of configuration changes, including pushed file contents and sensitive encryption keys. By injecting forged logs, an attacker can execute arbitrary commands across all replicas, permanently delete projects, or re-encrypt data with attacker-controlled keys. The blast radius covers all services and microservices that consume data from the compromised Central Dogma instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize immediate audit of Central Dogma configurations across all production and staging environments to ensure a unique, complex \u003ccode\u003ereplication.secret\u003c/code\u003e is explicitly defined. Implement network segmentation and firewall rules to strictly limit access to the ZooKeeper quorum ports (defaulting to the ports configured in \u003ccode\u003ereplication.servers\u003c/code\u003e) to known peer IP addresses only. Upgrade to a patched version that removes the silent fallback mechanism and enforces explicit secret definition.\u003c/p\u003e\n","date_modified":"2026-09-12T00:57:10Z","date_published":"2026-09-12T00:57:10Z","id":"https://feed.craftedsignal.io/briefs/2026-09-central-dogma-secret/","summary":"Central Dogma uses a hard-coded ZooKeeper replication secret that allows unauthenticated network actors to access configuration logs, perform session forgery, and gain cluster-wide command execution.","title":"Hard-coded Replication Secret in Central Dogma Enables Cluster Takeover","url":"https://feed.craftedsignal.io/briefs/2026-09-central-dogma-secret/"}],"language":"en","title":"CraftedSignal Threat Feed - Central-Dogma","version":"https://jsonfeed.org/version/1.1"}