apache / apache/libcloud

Potential Cryptography Issues in file `libcloud/compute/drivers/vsphere.py`

オープン
#1,945 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
2.1k
フォーク
931
平均マージ
1日 2時間
マージ済み PR(30日)
4

説明

## Summary
This bug report is created by manually analyzing the source codes based on two fixes generated by Intelligent Code Repair tool (iCR).

## Detailed Information
- Python: 3.8.10
- OS: Ubuntu 20.04

# Suggested Fix 1

In your project file [libcloud/compute/drivers/vsphere.py](https://github.com/apache/libcloud/blob/trunk/libcloud/compute/drivers/vsphere.py) on Line 111, there’s a code segment that goes-

```py
context = ssl.create_default_context(cafile=ca_cert)
self.connection = connect.SmartConnect(
host=host,
port=port,
user=username,
pwd=password,
sslContext=context,
)
```

While triaging your repository, we noticed that the `connect.SmartConnect` method from `pyVim` library uses a method called `Connect` that calls a method called `__Login` which creates a `SoapStubAdapter` class object. A comment on that class on Line [1380 - 1384](https://github.com/vmware/pyvmomi/blob/master/pyVmomi/SoapAdapter.py#L1380) goes-

```py
# @param sslContext SSL Context describing the various SSL options. It is
# only supported in Python 2.7.9 or higher.
# if sslContext is used, load cert & key to the context with API
# sslContext = ssl.create_default_context(cafile=ca_cert_file)
# sslContext.load_cert_chain(key_file, cert_file)
```

However, in your source file the Certificate Chain isn’t loaded into `sslContext` object. We suggest that you load the certificate chain into the `sslContext` object as mentioned in the comments.

# Suggested Fix 2

In the same [file](https://github.com/apache/libcloud/blob/trunk/libcloud/compute/drivers/vsphere.py#L134) on Line 131 - 135, it goes-

```py
if "certificate verify failed" in error_message:
# bypass self signed certificates
try:
context = ssl.SSLContext(ssl.PROTOCOL_SSLv23)
context.verify_mode = ssl.CERT_NONE
```

Now, it says here that the following code is to bypass the self-signed certificates. In this case, the official [documentation for ssl](https://docs.python.org/3/library/ssl.html#ssl.PROTOCOL_SSLv23) says-

> `ssl.PROTOCOL_SSLv23`
> Alias for `PROTOCOL_TLS`.
> Deprecated since version 3.6: Use `PROTOCOL_TLS` instead.

To clear the confusion, it’s suggested that you use `PROTOCOL_TLS` while instantiating the `context` object. However, if the code is used for some other reason that bypassing self-signed certificates, please let us have a discussion.

### CLA Requirements:

This section is only relevant if your project requires contributors to sign a Contributor License Agreement (CLA) for external contributions.

All contributed commits are already automatically signed off.

The meaning of a signoff depends on the project, but it typically certifies that committer has the rights to submit this work under the same license and agrees to a Developer Certificate of Origin (see https://developercertificate.org/ for more information).

- [Git Commit Sign Off documentation](https://developercertificate.org/)

### Sponsorship and Support

This work is done by the security researchers from OpenRefactory and is supported by the [Open Source Security Foundation (OpenSSF)](https://openssf.org/): [Project Alpha-Omega](https://alpha-omega.dev/). Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed - to improve global software supply chain security.

The bug is found by running the iCR tool by [OpenRefactory, Inc.](https://openrefactory.com/) and then manually triaging the results.

コントリビューションガイド

コントリビューションガイドを開く

調査の方向性

まず libcloud/compute/drivers/vsphere.py の指定された行 111 および 131-135 から始め、リンクされている pyVmomi SoapAdapter のコメントと Python ssl のドキュメントを確認してください。変更を加える前に、証明書チェーンの想定される動作と TLS プロトコル定数について maintainers に確認してください。完了とは、2 つの指摘が解決されるか、その想定される動作が明確に文書化されている状態を意味します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
backend, cloud, security
issue の種類
バグ
難易度
4/5
見積もり時間
3〜5日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
35/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。