Fabio Burzigotti created WSS-733:
------------------------------------
Summary: Loader.loadInputStream() unprivileged access to FileSystem
Key: WSS-733
URL: https://issues.apache.org/jira/browse/WSS-733
Project: WSS4J
Issue Type: Bug
Components: WSS4J Core
Affects Versions: 4.0.2, 3.0.6
Reporter: Fabio Burzigotti
Assignee: Colm O hEigeartaigh
Loader.loadInputStream [was recently modified to look into the file system
first|https://github.com/apache/ws-wss4j/commit/6c3257a83caa9c11e4af4af6b675e26f59b921f5#diff-92c555b5294f2b7f20fe8460a7dfb94cec05406ed7367f2376367b88d63d8c7cR43-R83],
while it was once doing that as the last option.
We tried to update WSS4J from 3.0.5 to 3.0.6 in JBoss EAP 8.1 and we're hitting
security exceptions due to missing permissions on tests running with the
Security Manager enabled:
{code:java}
...
ERROR [stderr] (default task-1) java.security.AccessControlException:
WFSM000001: Permission check failed (permission "("java.io.FilePermission"
"/home/jenkins/workspace/testsuite/integration/ws/xcatalog" "read")" in code
source
"(vfs:/content/jaxws-samples-wsse-policy-trust-onbehalfof.war/WEB-INF/classes
<no signer certificates>)" of "ModuleClassLoader for Module
"deployment.jaxws-samples-wsse-policy-trust-onbehalfof.war" from Service Module
Loader")
...{code}
Deployments break unless such permissions are added to them by the user, which
configures a regression.
The change landed in 4.0.2 and in 3.0.6 (at least, I didn't check other tags).
One argument could be about the Security Manager APIs going to be removed, but
in maintenance branches like 3.0.x this issue is currently blocking the WSS4J
upgrade that would resolve many CVEs.
The {{Loader}} class uses to call Security Manager APIs - i.e.
{{doPrivileged()-}} already in some cases.
Would it be a viable option to fix by wrapping the meaningful code blocks, like
the file system access in this very case, into {{doPrivileged()}} calls, at
least for 3.0.6+?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]