Hacktoberfest 2026: the issues maintainers tagged for October, open and beginner-friendly. Browse Hacktoberfest issues

CWE-295: TLS verification disabled in K8s strategy fallback — verify_none when ca.crt missing, Bearer token exposed

Open Beginner friendly
#214 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Assessment

Difficulty
2/5
Estimated time
1-3 hours
Newbie friendliness
78/100
Issue type
Bug
Clarity
Clearly specified
Activity status
Quiet
Tech stack
elixir, kubernetes

Research direction

Start in lib/strategy/kubernetes.ex:323-337 at get_ssl_opts/1 and trace how its returned options reach the Kubernetes HTTP request. Ensure the missing-ca.crt path no longer disables certificate verification, then run the relevant project tests to confirm the fallback preserves peer verification.

Written by the indexing model from the issue text.

Description

Summary

The Kubernetes clustering strategy's get_ssl_opts/1 function falls back to verify: :verify_none when the service account's ca.crt file is missing. This means K8s API Bearer tokens are transmitted over TLS connections that accept any certificate.

Vulnerable Code (lib/strategy/kubernetes.ex:323-337)
defp get_ssl_opts(service_account_path) do
  path = Path.join(service_account_path, "ca.crt")
  case File.exists?(path) do
    true  -> [verify: :verify_peer, cacertfile: String.to_charlist(path)]
    false -> [verify: :verify_none]    # ← DANGEROUS FALLBACK
  end
end
Credential Flow
  • verify: :verify_none is passed as SSL options to :httpc.request()
  • The K8s service account Bearer token is sent via Authorization: Bearer {token} header
  • All K8s API responses (pod lists, ConfigMaps, Secrets) transit over unverified TLS
Impact

MITM attacker can capture the K8s service account token, gaining API access within the cluster — pod enumeration, ConfigMap/Secret access, lateral movement.

Fix

Never fall back to verify_none. Use system CA store instead:

false -> [verify: :verify_peer]  # Use system CA, don't disable verification
Severity

CVSS 7.4 (HIGH) — CWE-295: Improper Certificate Validation

Dominant language
Elixir
Stars
2.2k
Forks
202
PR merge metrics
No merged PRs in 30d

Getting set up

  • No Dockerfile or Docker Compose file
  • Has a pull request template
  • No contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from bitwalker/libcluster

All issues in bitwalker/libcluster

Similar issues

More Elixir issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.