T09 · Insecure Skill Coding Practices
- Location
src/icalendar_sync/calendar.py:723- Finding
iCloud credentials can be transmitted to an arbitrary CalDAV endpoint
- Content
View full analysis
str: current_url = self.base_url if not self.username or not self.password or requests is None: return current_url max_redirects = 5 timeout = 15 session = requests.Session() auth_header = "Basic " + base64.b64encode( f"{self.username}:{self.password}".encode("utf-8") ).decode("ascii") for _ in range(max_redirects): headers = self._build_request_headers(current_url) headers["Authorization"] = auth_header try: response = session.get( current_url, headers=headers, allow_redirects=False, timeout=timeout, ) self._capture_response_debug(response) except RequestException as exc: if self.debug_http: logger.debug("Endpoint resolution failed: %s", self._format_exception_details(exc)) break if response.status_code in (301, 302, 307, 308): location = response.headers.get("Location") if not location: break next_url = urljoin(current_url, location) next_host = (urlparse(next_url).hostname or "").lower() if next_host and next_host.endswith("icloud.com"): current_url = next_url continue break break return current_url ``` ### Technical Analysis The initial CalDAV URL is read from the `ICALENDAR_SYNC_CALDAV_URL` environment variable without validating its scheme or hostname. The code then ...[truncated 2693 chars]- Remediation
View remediation
str: parsed = urlparse(value) if parsed.scheme != "https": raise ValueError("CalDAV endpoint must use HTTPS") if parsed.username or parsed.password: raise ValueError("CalDAV endpoint must not contain user information") if (parsed.hostname or "").lower() != "caldav.icloud.com": raise ValueError("Unapproved CalDAV endpoint") return value ``` ]]>
