[CRITICAL] Passwordless sudo for wheel group on all hosts #11
Labels
No labels
area:documentation
area:infrastructure
area:network
area:security
priority:critical
priority:high
priority:low
priority:medium
status:blocked
type:bug
type:deployment
type:enhancement
type:investigation
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
reinitialized.net/infrastructure#11
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Labels:
area:security,priority:critical,type:bugDescription
In
modules/profiles/standard.nixline 79:This allows ALL users in the wheel group to execute ANY command as root without password verification.
Impact
CRITICAL — Combined with SSH key-based authentication, compromising any SSH private key of a wheel group user grants immediate, unauthenticated root access. There is no second factor of defense.
Attack vectors:
Recommended Fix
If passwordless operations are needed for automation (e.g., nixos-rebuild over SSH), use targeted NOPASSWD rules for specific commands rather than blanket passwordless sudo.