T09 · Insecure Skill Coding Practices
- Location
scripts/export_soap_to_excel.py:137- Finding
Unvalidated Salesforce Instance URL Enables SSRF and Session Token Disclosure
- Content
View full analysis
ET.Element: resp = self.session.post( self.endpoint, data=body.encode('utf-8'), headers=self.headers, timeout=120 ) ``` The endpoint and credential are loaded directly from a caller-supplied JSON file: ```python auth = json.loads(Path(args.auth_json).read_text(encoding='utf-8'))['result'] client = SoapClient(auth['instanceUrl'], auth['accessToken'], auth['apiVersion']) ``` The access token is subsequently embedded in every SOAP request: ```python {self.access_token} ``` ### Technical Analysis `instanceUrl` is accepted without checking its scheme, hostname, port, or relationship to an approved Salesforce domain. The value is concatenated into a request endpoint and passed directly to `requests.Session.post()`. A crafted authentication JSON file can therefore redirect SOAP requests to an attacker-controlled server or an internal network service. Because the SOAP body contains the Salesforce session token, an attacker controlling the destination receives the token in plaintext at the HTTP application layer. The code also does not explicitly require HTTPS. A supplied `http://` URL would transmit the session token without transport encryption. The `requests` client follows redire ...[truncated 1789 chars]- Remediation
View remediation
