Hacktoberfest 2026: le issue che i maintainer hanno segnato per ottobre, aperte e adatte ai principianti. Sfoglia le issue Hacktoberfest

HTTP runner defaults to verify=False, disabling TLS certificate validation (CWE-295)

Aperta Adatta ai principianti
#6,389 0 commenti 0 reazioni 0 assegnatari Vedi su GitHub

Nessuno ha ancora preso questa issue.

Valutazione

Difficoltà
2/5
Tempo stimato
1-3 ore
Idoneità per principianti
76/100
Tipo di issue
Bug
Chiarezza
Specificata chiaramente
Stato di attività
Tranquilla
Stack tecnologico
python
Ambito
security

Direzione di ricerca

Inizia in contrib/runners/http_runner/http_runner/http_runner.py, nel costruttore dell’HTTP runner intorno alla riga 203, e verifica come l’argomento verify viene passato alle richieste in uscita. Conferma che il valore predefinito convalida i certificati TLS, mentre verify=false rimane disponibile in modo esplicito, quindi esegui i test esistenti dell’HTTP runner, se disponibili.

Scritto dal modello di indicizzazione a partire dal testo della issue.

Descrizione

Summary

The HTTP runner (http_runner) defaults to verify=False for all outbound HTTP requests, disabling TLS certificate validation. This makes any action using the HTTP runner vulnerable to man-in-the-middle attacks by default.

Affected File

contrib/runners/http_runner/http_runner/http_runner.py (line 203)

def __init__(
    self,
    url=None,
    method=None,
    body="",
    params=None,
    headers=None,
    cookies=None,
    auth=None,
    timeout=60,
    allow_redirects=False,
    proxies=None,
    files=None,
    verify=False,  # <-- TLS verification disabled by default
    username=None,
    password=None,
    url_hosts_blacklist=None,
    url_hosts_whitelist=None,
):

Impact

The HTTP runner is one of the most commonly used runners in StackStorm. Any action using core.http or the HTTP runner will skip TLS certificate validation unless the user explicitly passes verify=true. This means:

  • Connections to HTTPS endpoints do not verify the server's certificate chain
  • An attacker in a network position to intercept traffic can perform man-in-the-middle attacks
  • Credentials, API tokens, and sensitive payloads sent via the HTTP runner can be intercepted

This is particularly concerning in datacenter and infrastructure automation contexts where the HTTP runner is used to interact with management APIs (e.g., cloud providers, network devices, internal services).

Recommended Fix

Change the default to verify=True:

def __init__(self, url=None, method=None, ..., verify=True, ...):

Users who need to disable verification for specific endpoints (e.g., self-signed certs in lab environments) can still pass verify=false explicitly. This follows the principle of secure-by-default.

If backward compatibility is a concern, consider:

  1. Adding a deprecation warning when verify=false is used without being explicitly set
  2. Adding a configuration option in st2.conf to control the default globally

References

  • CWE-295: Improper Certificate Validation
  • Discovered via manual code review
Lingua principale
Python
Stelle
6.5k
Fork
788
Merge medio
1m
PR unite (30g)
1

Preparare l'ambiente

Come iniziare

  1. Leggi tutta la issue e poi la guida ai contributi del progetto.
  2. Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
  3. Fai un fork del repository e lavora su un branch.
  4. Apri una pull request che faccia riferimento al numero della issue.

Altre issue di StackStorm/st2

Tutte le issue di StackStorm/st2

Issue simili

Altre issue su Python

Ricevi le nuove issue nella tua casella

Un breve riepilogo di issue GitHub adatte ai principianti.