T09 · Insecure Skill Coding Practices
- Location
bw.sh:184- Finding
Sensitive authentication data may be transmitted to an untrusted or plaintext endpoint
- Content
View full analysis
/dev/null 2>&1 || true ``` ```python # Submit registration r = requests.post(f'{server}/api/accounts/register', json={ 'name': name, 'email': email, 'masterPasswordHash': master_password_hash, 'masterPasswordHint': '', 'key': encrypted_key, 'kdf': 0, 'kdfIterations': kdf_iterations, }, timeout=30) ``` ### Technical Analysis The script accepts `BW_SERVER` from an environment variable or credential file and uses it without validating its scheme, hostname, port, or URL structure. The value is supplied both to the Bitwarden CLI and directly to `requests.post`. The registration request contains the account email, master-password verifier, encrypted account key, and key-derivation parameters. Base64 encoding of `masterPasswordHash` is required by the Bitwarden-compatible registration protocol and is not, by itself, evidence of covert exfiltration. Nevertheless, the verifier remains sensitive authentication material. The project documentation states that communication uses HTTPS, but the implementation does not enforce that requirement. A value such as `http://attacker.example` is accepted. The endpoint may also be changed to an arbitrary HTTPS server controlled by an attacker. TLS certificate verification by `requests` protects correctly configured HTTPS connections but does not protect against an intentionally or maliciously changed destination. Network transmission is necessary for the declared Bitwarden/Vaultwarden functionality. The issue is that the implementation grants the configured endpoint unrestricted control over where authentication material is sent, exceeding a safe least-privilege design unless the configuration is strongly protected and validated. ...[truncated 1327 chars]- Remediation
View remediation
