Severity: medium Category: security Location:src/shared/transport_tls.c:134-161
Description: client_connect_tls() sets up SSL verification when a CA is provided (SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL)), but it never calls SSL_set1_host() or SSL_set_verify() with hostname verification. An attacker with a valid certificate for evil.com (signed by the configured CA) can impersonate the intended server myserver.example.com.
Suggested fix:
After creating the SSL object and before SSL_connect(), set the expected hostname:
Verify the result with SSL_get_verify_result(ssl) after the handshake and check that hostname verification succeeded. Alternatively, call SSL_verify_client_post_handshake() semantics or inspect the peer certificate.
Labels: security, tls
**Severity:** medium
**Category:** security
**Location:** `src/shared/transport_tls.c:134-161`
**Description:**
`client_connect_tls()` sets up SSL verification when a CA is provided (`SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL)`), but it never calls `SSL_set1_host()` or `SSL_set_verify()` with hostname verification. An attacker with a valid certificate for `evil.com` (signed by the configured CA) can impersonate the intended server `myserver.example.com`.
**Suggested fix:**
After creating the SSL object and before `SSL_connect()`, set the expected hostname:
```c
SSL_set1_host(ssl, host);
SSL_set_hostflags(ssl, X509_CHECK_FLAG_NO_PARTIAL_WILDCARDS);
```
Verify the result with `SSL_get_verify_result(ssl)` after the handshake and check that hostname verification succeeded. Alternatively, call `SSL_verify_client_post_handshake()` semantics or inspect the peer certificate.
**Labels:** security, tls
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: medium
Category: security
Location:
src/shared/transport_tls.c:134-161Description:
client_connect_tls()sets up SSL verification when a CA is provided (SSL_CTX_set_verify(ctx, SSL_VERIFY_PEER, NULL)), but it never callsSSL_set1_host()orSSL_set_verify()with hostname verification. An attacker with a valid certificate forevil.com(signed by the configured CA) can impersonate the intended servermyserver.example.com.Suggested fix:
After creating the SSL object and before
SSL_connect(), set the expected hostname:Verify the result with
SSL_get_verify_result(ssl)after the handshake and check that hostname verification succeeded. Alternatively, callSSL_verify_client_post_handshake()semantics or inspect the peer certificate.Labels: security, tls