cookbooks / ic-graphite

A Chef cookbook for graphite (Initial Upstream: infochimps-labs, Repository: ironfan-pantry)
https://github.com/infochimps-labs/ironfan-pantry
Apache License 2.0
0 stars 2 forks source link

Update database_mysql.rb #3

Open akondasif opened 5 years ago

akondasif commented 5 years ago

Greetings,

I am a security researcher, who is looking for coding patterns that are indicative of security weaknesses in Chef scripts. In your repo I found instances of MD5 usage within Chef scripts. MD5 is breakable (http://merlot.usc.edu/csac-f06/papers/Wang05a.pdf). According to the Common Weakness Enumeration organization this is a security weakness (CWE-327: Use of a Broken or Risky Cryptographic Algorithm https://cwe.mitre.org/data/definitions/327.html).

MD5 has security weaknesses, better to use SHA 512. Any feedback is welcome. Addresses issue: https://github.com/cookbooks/ic-graphite/issues/1