T09 · Insecure Skill Coding Practices
- Location
scripts/gitlab_report.py:24- Finding
TLS certificate validation is globally disabled for authenticated network requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/gitlab_report.py, lines 24–27, 41–48, and 578–586
Vulnerability Type: Improper certificate validation
Risk Level: HighVulnerable Code
python _SSL_CTX = ssl.create_default_context() _SSL_CTX.check_hostname = False _SSL_CTX.verify_mode = ssl.CERT_NONEpython def gitlab_get(config, path, max_retries=2): url = f"{config['gitlab_url'].rstrip('/')}/api/v4{path}" req = urllib.request.Request( url, headers={"PRIVATE-TOKEN": config["gitlab_token"]} ) for attempt in range(max_retries): try: with urllib.request.urlopen( req, timeout=20, context=_SSL_CTX ) as resp: return json.loads(resp.read().decode())python def send_feishu(webhook_url: str, message: Dict): data = json.dumps(message).encode("utf-8") req = urllib.request.Request( webhook_url, data=data, headers={"Content-Type": "application/json"}, method="POST" ) try: with urllib.request.urlopen( req, timeout=15, context=_SSL_CTX ) as resp: result = json.loads(resp.read().decode())Technical Analysis
The shared SSL context disables both certificate-chain verification and hostname validation. It is used for authenticated GitLab API requests and outbound webhook requests.
HTTPS only provides endpoint authentication when the client verifies that the certificate was issued by a trusted authority and belongs to the requested hostname. With
CERT_NONEand hostname checking disabled, the script accepts any certificate presented by a remote endpoint.The GitLab Personal Access Token is placed in the
PRIVATE-TOKENrequest header. A network attacker capable of intercepting traffic can impersonate the co ...[truncated 1925 chars]- Remediation
View remediation
Remediation Suggestions
-
Remove the globally insecure SSL context:
python _SSL_CTX = ssl.create_default_context()Do not alter
check_hostnameorverify_mode. -
For private GitLab deployments using an internal certificate authority, support an explicit CA bundle:
python ca_file = config.get("ca_bundle") ssl_context = ssl.create_default_context(cafile=ca_file) -
Do not provide a configuration option that disables certificate validation. If an exceptional development-only override is unavoidable, it must be disabled by default, produce a prominent warning, and never be permitted in production.
-
Require HTTPS for GitLab and webhook URLs.
-
Rotate any GitLab token that may previously have been transmitted over an intercepted or untrusted network.
-
Use a narrowly scoped project or group access token with only the read permissions required by the report.
-
Add automated tests that verify invalid, expired, self-signed, and hostname-mismatched certificates are rejected.
-
