Improper x.509 certificate validation in extensions of X509TrustManager with general conditions
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 3.4k
- Forks
- 663
- PR merge metrics
- No merged PRs in 30d
Description
We found that we could not detect some potential cryptographic vulnerabilities. We believe this may be due to underlying implementation or design gaps.
Here are the details of our analysis and the cryptographic misuses:
Using QARK version 4.0.0
Using Python version 3.5.2
Using OpenJDK version 1.8.0_232 64 bit
Running on Ubuntu: 18.04 Kernel: 4.4.0-174-generic
Each cryptographic vulnerability was generated as a barebones Java project that only contained a single vulnerability in the main function and used up to two java source files. Additionally, all cryptographic API calls were from Java Cryptographic Architecture (JCA).
We are reporting this since in your readme you mention that “Improper x.509 certificate validation” is attempted to be found.
Attempting to use an insecure validation of an overridden checkServerTrusted method that is created within an anonymous inner class object created from an empty abstract class which implements the X509TrustManager interface from JCA, which we believe is due to not detecting security exceptions thrown under impossible conditions; e.g., if(!(true || arg0== null || arg1 == null)) throw new CertificateException();
public abstract class BareboneTrustManagerExt implements javax.net.ssl.X509TrustManager{
}
public class BareboneTrustManagerConditional {
static final X509Certificate[] EMPTY_X509CERTIFICATE_ARRAY = new X509Certificate[] {};
public static void main(String[] args) {
TrustManager[] trustAll = new TrustManager[] {
new BareboneTrustManagerExt() {
@java.lang.Override
public void checkClientTrusted(java.security.cert.X509Certificate[] arg0, java.lang.String arg1)
throws java.security.cert.CertificateException {
if(!(true||arg0 == null||arg1 == null)){
throw new java.security.cert.CertificateException();
}
}
@java.lang.Override
public void checkServerTrusted(java.security.cert.X509Certificate[] arg0, java.lang.String arg1)
throws java.security.cert.CertificateException {
if(!(true||arg0 == null||arg1 == null)){
throw new java.security.cert.CertificateException();
}
}
@Override
public X509Certificate[] getAcceptedIssuers() {
for(int i = 0; i<100; i++){
if (i==50)
return EMPTY_X509CERTIFICATE_ARRAY;;
}
return EMPTY_X509CERTIFICATE_ARRAY;
}
}
};
SSLContext context;
try {
context = SSLContext.getInstance("TLS");
context.init(null, trustAll, new SecureRandom());
} catch (NoSuchAlgorithmException e) {
// TODO Auto-generated catch block
// e.printStackTrace();
} catch (KeyManagementException e) {
// TODO Auto-generated catch block
// e.printStackTrace();
}
System.out.println("Hello World 8.6");
}
}
Please let me know if you need any additional information (e.g., logs from our side) in fixing these issues.
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start with QARK's README section for improper X.509 certificate validation and reproduce the supplied Java example using the reported QARK, Python, and OpenJDK versions. Trace how anonymous X509TrustManager implementations and conditional CertificateException paths are analyzed. Done means this example is detected and reported as an improper certificate-validation vulnerability.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java, python
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100