Skip to content

Introduced Safer FTP Alternative: Added FTP_TLS#2877

Open
nydelzaf wants to merge 1 commit intomotioneye-project:python2from
nydelzaf:Fix_Weak_Crypto_FTP
Open

Introduced Safer FTP Alternative: Added FTP_TLS#2877
nydelzaf wants to merge 1 commit intomotioneye-project:python2from
nydelzaf:Fix_Weak_Crypto_FTP

Conversation

@nydelzaf
Copy link

Details

While triaging your project, our bug fixing tool generated the following message(s)-

In file: uploadservices.py, method: _get_conn, a clear-text protocol such as FTP, Telnet or SMTP is used. These protocols transfer data without any encryption, which expose applications to a large range of risks. iCR suggested that data should be transferred over only secure transport channels.

Changes

  • Added FTP_TLS support to upload services

Previously Found & Fixed

CLA Requirements

This section is only relevant if your project requires contributors to sign a Contributor License Agreement (CLA) for external contributions.

All contributed commits are already automatically signed off.

The meaning of a signoff depends on the project, but it typically certifies that committer has the rights to submit this work under the same license and agrees to a Developer Certificate of Origin (see https://developercertificate.org/ for more information).
- Git Commit SignOff documentation

Sponsorship and Support

This work is done by the security researchers from OpenRefactory and is supported by the Open Source Security Foundation (OpenSSF): Project Alpha-Omega. Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed – to improve global software supply chain security.

The bug is found by running the Intelligent Code Repair (iCR) tool by OpenRefactory and then manually triaging the results.

Signed-off-by: fazledyn-or <ataf@openrefactory.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Development

Successfully merging this pull request may close these issues.

2 participants