Summary
This bug report is created by manually analyzing the source codes based on two fixes generated by Intelligent Code Repair tool (iCR).
Detailed Information
- Python: 3.8.10
- OS: Ubuntu 20.04
Suggested Fix 1
In your project file libcloud/compute/drivers/vsphere.py on Line 111, there’s a code segment that goes-
context = ssl.create_default_context(cafile=ca_cert)
self.connection = connect.SmartConnect(
host=host,
port=port,
user=username,
pwd=password,
sslContext=context,
)
While triaging your repository, we noticed that the connect.SmartConnect method from pyVim library uses a method called Connect that calls a method called __Login which creates a SoapStubAdapter class object. A comment on that class on Line 1380 - 1384 goes-
# @param sslContext SSL Context describing the various SSL options. It is
# only supported in Python 2.7.9 or higher.
# if sslContext is used, load cert & key to the context with API
# sslContext = ssl.create_default_context(cafile=ca_cert_file)
# sslContext.load_cert_chain(key_file, cert_file)
However, in your source file the Certificate Chain isn’t loaded into sslContext object. We suggest that you load the certificate chain into the sslContext object as mentioned in the comments.
Suggested Fix 2
In the same file on Line 131 - 135, it goes-
if "certificate verify failed" in error_message:
# bypass self signed certificates
try:
context = ssl.SSLContext(ssl.PROTOCOL_SSLv23)
context.verify_mode = ssl.CERT_NONE
Now, it says here that the following code is to bypass the self-signed certificates. In this case, the official documentation for ssl says-
ssl.PROTOCOL_SSLv23
Alias for PROTOCOL_TLS.
Deprecated since version 3.6: Use PROTOCOL_TLS instead.
To clear the confusion, it’s suggested that you use PROTOCOL_TLS while instantiating the context object. However, if the code is used for some other reason that bypassing self-signed certificates, please let us have a discussion.
CLA Requirements:
This section is only relevant if your project requires contributors to sign a Contributor License Agreement (CLA) for external contributions.
All contributed commits are already automatically signed off.
The meaning of a signoff depends on the project, but it typically certifies that committer has the rights to submit this work under the same license and agrees to a Developer Certificate of Origin (see https://developercertificate.org/ for more information).
Sponsorship and Support
This work is done by the security researchers from OpenRefactory and is supported by the Open Source Security Foundation (OpenSSF): Project Alpha-Omega. Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed - to improve global software supply chain security.
The bug is found by running the iCR tool by OpenRefactory, Inc. and then manually triaging the results.
Summary
This bug report is created by manually analyzing the source codes based on two fixes generated by Intelligent Code Repair tool (iCR).
Detailed Information
Suggested Fix 1
In your project file libcloud/compute/drivers/vsphere.py on Line 111, there’s a code segment that goes-
While triaging your repository, we noticed that the
connect.SmartConnectmethod frompyVimlibrary uses a method calledConnectthat calls a method called__Loginwhich creates aSoapStubAdapterclass object. A comment on that class on Line 1380 - 1384 goes-However, in your source file the Certificate Chain isn’t loaded into
sslContextobject. We suggest that you load the certificate chain into thesslContextobject as mentioned in the comments.Suggested Fix 2
In the same file on Line 131 - 135, it goes-
Now, it says here that the following code is to bypass the self-signed certificates. In this case, the official documentation for ssl says-
To clear the confusion, it’s suggested that you use
PROTOCOL_TLSwhile instantiating thecontextobject. However, if the code is used for some other reason that bypassing self-signed certificates, please let us have a discussion.CLA Requirements:
This section is only relevant if your project requires contributors to sign a Contributor License Agreement (CLA) for external contributions.
All contributed commits are already automatically signed off.
The meaning of a signoff depends on the project, but it typically certifies that committer has the rights to submit this work under the same license and agrees to a Developer Certificate of Origin (see https://developercertificate.org/ for more information).
Sponsorship and Support
This work is done by the security researchers from OpenRefactory and is supported by the Open Source Security Foundation (OpenSSF): Project Alpha-Omega. Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed - to improve global software supply chain security.
The bug is found by running the iCR tool by OpenRefactory, Inc. and then manually triaging the results.