T09 · Insecure Skill Coding Practices
- Location
scripts/ges_graph_skill.py:138- Finding
Cloud credentials, bearer tokens, and graph data use unauthenticated or plaintext network transport
- Content
View full analysis
Vulnerability Details
File Location:
scripts/ges_graph_skill.py:138-179, 191-250, 329-367, 506-541;scripts/ges_graph_skill.js:545-603
Vulnerability Type: Disabled TLS certificate verification and plaintext authenticated API transport
Risk Level: HighTechnical Analysis
The Python authentication paths explicitly disable TLS certificate verification when sending either the user's password or an AK/SK-authenticated request to the configured IAM endpoint:
python def _fetch_token_by_password(self, username: str, password: str, domain_name: str = None) -> str: url = self.config.get('iam_url') project_id = self.config.get('project_id') if not url: raise Exception("ges_env.csv中缺少iam_url配置") headers = {'Content-Type': 'application/json'} if domain_name: data = { 'auth': { 'identity': { 'methods': ['password'], 'password': { 'user': { 'name': username, 'password': password, 'domain': {'name': domain_name} } } }, 'scope': {'project': {'id': project_id}} } } else: data = { 'auth': { 'identity': { 'methods': ['password'], 'password': { 'user': { 'name': username, 'password': password } } }, 'scope': {'project': {'id': project_id}} } } resp = requests.post(url, headers=headers, json=data, timeout=30, verify=False)The AK/SK authentication request is similarly sent with certificate verification disabled:
python headers = { 'Accept': 'application/json', 'Content-Type': C ...[truncated 4119 chars]- Remediation
View remediation
Remediation Suggestions
- Require HTTPS for IAM, OBS, and GES endpoints. Reject an
iam_urlor service URL whose scheme is nothttps:. - Remove every
verify=Falseargument from Python requests and do not globally suppressInsecureRequestWarning. - Remove
rejectUnauthorized: falsefrom Node.js request options. - Use the operating system's trusted CA store by default. If a private GES deployment uses an internal CA, accept an explicit CA bundle path rather than disabling validation.
- Make the GES scheme configurable but secure by default, and reject plaintext HTTP outside a separately enabled, clearly documented local-development mode.
- Apply strict hostname validation and avoid automatically following authentication requests to unrelated hosts.
- Add automated tests that confirm invalid, expired, and hostname-mismatched certificates are rejected.
- Rotate any credentials or tokens that have previously traversed an untrusted network using the vulnerable implementation.
- Require HTTPS for IAM, OBS, and GES endpoints. Reject an
