Environment
- CP version: v0.9.4 (commit
f925e5f6)
- OS: any
- Platform: container / VM
Description
cpdaemon connects to the CPM with server certificate verification disabled, with no switch to turn it on:
cpdaemon/cmd/internal/asm/provider.go:114 → InsecureSkipVerify: true
Anyone able to man-in-the-middle the CPM channel can present any self-signed certificate and return forged JSON. Those responses drive task creation, BPF expressions, forward hosts and output targets on the probe - so this is a remotely influenceable channel, not a locally visible issue.
Steps to reproduce
- Run a fake CPM HTTPS server with a self-signed certificate.
- Point
cpm.base_url at it.
cpdaemon completes the handshake and accepts its responses (no certificate error).
Expected
Verify the server certificate by default (allow turning it off explicitly), and support mTLS. (Note: PKCS#12 client certs are only used in the provider.go:116 branch, which is orthogonal to server verification.)
Actual
Unconditional InsecureSkipVerify: true; there is no config to enable verification.
Notes
Found by source review while writing an independent Rust port; the threat model and a temporary mitigation (dedicated management network / local reverse proxy that validates the upstream certificate) are documented in that port's SECURITY.md.
中文原文
测试环境
- CP 版本:v0.9.4(commit
f925e5f6)
- 操作系统:任意
- 运行平台:容器 / 虚拟机
问题描述
cpdaemon 连接 CPM 时无条件关闭了 TLS 证书校验,且没有开关:
cpdaemon/cmd/internal/asm/provider.go:114 → InsecureSkipVerify: true
任何能对 CPM 通道做中间人的一方,都可以用任意自签证书冒充 CPM 并返回伪造的 JSON;而这些响应会驱动探针创建采集任务、下发 BPF 表达式 / 转发主机 / 输出目标。即:这是可远程影响探针行为的通道,而不是仅本地可见的问题。
重现方法
- 起一个"假 CPM" HTTPS 服务端(自签证书);
- 配置
cpm.base_url 指向它;
- 观察
cpdaemon 正常握手并接受其响应(无证书错误)。
期望
默认校验服务端证书(允许显式配置关闭),并支持 mTLS。(注:PKCS#12 客户端证书仅在配置了 cert 时于 provider.go:116 分支使用,与"是否校验服务端"是两件事。)
实际
无条件 InsecureSkipVerify: true,无法通过配置开启校验。
附件 / 说明
本条由独立 Rust 移植过程中的源码对照发现;威胁模型与临时缓解(专用管理网 / 本地反代校验上游证书)亦记录在移植仓库的 SECURITY.md。
Environment
f925e5f6)Description
cpdaemonconnects to the CPM with server certificate verification disabled, with no switch to turn it on:cpdaemon/cmd/internal/asm/provider.go:114→InsecureSkipVerify: trueAnyone able to man-in-the-middle the CPM channel can present any self-signed certificate and return forged JSON. Those responses drive task creation, BPF expressions, forward hosts and output targets on the probe - so this is a remotely influenceable channel, not a locally visible issue.
Steps to reproduce
cpm.base_urlat it.cpdaemoncompletes the handshake and accepts its responses (no certificate error).Expected
Verify the server certificate by default (allow turning it off explicitly), and support mTLS. (Note: PKCS#12 client certs are only used in the
provider.go:116branch, which is orthogonal to server verification.)Actual
Unconditional
InsecureSkipVerify: true; there is no config to enable verification.Notes
Found by source review while writing an independent Rust port; the threat model and a temporary mitigation (dedicated management network / local reverse proxy that validates the upstream certificate) are documented in that port's
SECURITY.md.中文原文
测试环境
f925e5f6)问题描述
cpdaemon连接 CPM 时无条件关闭了 TLS 证书校验,且没有开关:cpdaemon/cmd/internal/asm/provider.go:114→InsecureSkipVerify: true任何能对 CPM 通道做中间人的一方,都可以用任意自签证书冒充 CPM 并返回伪造的 JSON;而这些响应会驱动探针创建采集任务、下发 BPF 表达式 / 转发主机 / 输出目标。即:这是可远程影响探针行为的通道,而不是仅本地可见的问题。
重现方法
cpm.base_url指向它;cpdaemon正常握手并接受其响应(无证书错误)。期望
默认校验服务端证书(允许显式配置关闭),并支持 mTLS。(注:PKCS#12 客户端证书仅在配置了 cert 时于
provider.go:116分支使用,与"是否校验服务端"是两件事。)实际
无条件
InsecureSkipVerify: true,无法通过配置开启校验。附件 / 说明
本条由独立 Rust 移植过程中的源码对照发现;威胁模型与临时缓解(专用管理网 / 本地反代校验上游证书)亦记录在移植仓库的
SECURITY.md。