T09 · Insecure Skill Coding Practices
- Location
scripts/search_user.py:51- Finding
TLS Certificate Verification Disabled for Authenticated API Requests
- Content
View full analysis
Vulnerability Details
File Location:
scripts/search_user.py:51-55,scripts/work_list.py:49-53
Vulnerability Type: Improper TLS certificate validation
Risk Level: HighComplete Code Snippet
The same vulnerable TLS configuration appears in both scripts:
python def _ssl_context(): """Create an SSL context compatible with multiple environments.""" try: ctx = ssl.create_default_context() ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE except Exception: ctx = None return ctxThe resulting context is passed to authenticated HTTPS requests:
python req = urllib.request.Request( API_URL, data=payload, headers={ "Content-Type": "application/json", "X-API-Key": api_key, "User-Agent": "QoderWork/1.0", }, method="POST", ) ctx = _ssl_context() kwargs = {"timeout": 30} # 60 seconds in work_list.py if ctx: kwargs["context"] = ctx with urllib.request.urlopen(req, **kwargs) as resp: result = json.loads(resp.read().decode("utf-8"))Technical Analysis
Both scripts create a standard TLS context but then explicitly disable hostname checking and certificate verification. Consequently, the HTTPS connection encrypts traffic without authenticating the remote endpoint.
The requests include the user's
REDFOX_API_KEYin theX-API-Keyheader. Because any certificate is accepted, a network-positioned attacker can impersonateredfox.hk, terminate the TLS connection, and receive the API credential and request payload.The scripts also trust and parse the unauthenticated response as API data. This allows an interceptor to modify user records, work metadata, and externally displayed URLs. The issue is reachable whenever either script performs its normal API operation.
Attack Path
- A user invokes user search or work-list retrieval.
- The script loads
REDFOX_API_KEYfrom the environment or local configuration. - An attac ...[truncated 1055 chars]
- Remediation
View remediation
Remediation Suggestions
- Remove both statements that disable hostname and certificate validation:
python ctx.check_hostname = False ctx.verify_mode = ssl.CERT_NONE - Use the default verified context without modification:
python def _ssl_context(): return ssl.create_default_context() - Fail closed if a secure SSL context cannot be created rather than falling back to behavior that may weaken transport security.
- Ensure the runtime has an up-to-date trusted CA bundle instead of bypassing validation for compatibility.
- Apply the correction consistently in both
search_user.pyandwork_list.py. - Add tests confirming that certificates signed by an untrusted authority and certificates with a mismatched hostname are rejected.
- Rotate the API key if the vulnerable scripts have been used over an untrusted network.
- Remove both statements that disable hostname and certificate validation:
