T09 · Insecure Skill Coding Practices
- Location
scripts/flexus_lifecycle.py:331- Finding
TLS Certificate Verification Disabled for Privileged Cloud Operations
- Content
View full analysis
Vulnerability Details
File Location:
scripts/flexus_lifecycle.py, lines 331–334 and 460–468
Vulnerability Type: Improper certificate validation (CWE-295)
Risk Level: HighVulnerable code — lines 331–334:
python config = HttpConfig.get_default_config() config.ignore_ssl_verification = True client = BssClient.new_builder() \Vulnerable code — lines 460–468:
python resp = requests.request( signed_request.method, full_url, headers=signed_request.header_params, data=signed_request.body, verify=False, timeout=60 )Technical Analysis
The lifecycle client explicitly disables TLS certificate verification in two privileged request paths:
- The BSS SDK client used by renewal and unsubscribe operations is configured with
ignore_ssl_verification = True. - The direct HCSS request used to create an instance passes
verify=Falsetorequests.request.
Consequently, HTTPS encryption may still be negotiated, but the client does not authenticate the remote endpoint. An attacker able to intercept or redirect network traffic can present an arbitrary certificate without causing the requests to fail.
These requests contain signed authorization headers and, when temporary credentials are used, an
X-Security-Tokenheader. They also carry resource identifiers and account-changing requests involving purchases, renewals, or subscription cancellation.The issue is reachable during any non-dry-run create, renewal, or unsubscribe operation. The CLI confirmation mechanism limits accidental execution but does not protect the connection after the user authorizes the operation.
Attack Path
- The user authorizes a create, renewal, or unsubscribe operation and supplies Huawei Cloud credentials.
- An attacker with a network interception or traffic-redirection position redirects the relevant Huawei Cloud connection to an attacker-controlled TLS endpoint. ...[truncated 1171 chars]
- The BSS SDK client used by renewal and unsubscribe operations is configured with
- Remediation
View remediation
Remediation Suggestions
- Remove
config.ignore_ssl_verification = Trueand retain the Huawei Cloud SDK's default certificate validation. - Remove
verify=Falsefromrequests.request, allowing Requests to use its trusted CA store. - If an enterprise or private CA is required, accept an explicitly configured CA bundle and pass its path through the SDK configuration and
verifyparameter. Do not silently fall back to disabled verification. - Fail closed when certificate validation fails and return a sanitized error without retrying through an insecure transport.
- Add tests that verify invalid, expired, hostname-mismatched, and self-signed certificates are rejected across creation, renewal, and unsubscribe paths.
- Prefer current system and application CA bundles and document secure proxy configuration for environments that perform authorized TLS inspection.
- Remove
