[
https://issues.apache.org/jira/browse/WSS-733?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18124892#comment-18124892
]
Colm O hEigeartaigh commented on WSS-733:
-----------------------------------------
[~fburzigo] Yes please go ahead and submit a PR against 3.0.x for this.
> Loader.loadInputStream() unprivileged access to FileSystem
> ----------------------------------------------------------
>
> Key: WSS-733
> URL: https://issues.apache.org/jira/browse/WSS-733
> Project: WSS4J
> Issue Type: Bug
> Components: WSS4J Core
> Affects Versions: 3.0.6, 4.0.2
> Reporter: Fabio Burzigotti
> Assignee: Colm O hEigeartaigh
> Priority: Critical
>
> Loader.loadInputStream [was recently modified to look into the file system
> first|https://github.com/apache/ws-wss4j/commit/6c3257a83caa9c11e4af4af6b675e26f59b921f5#diff-92c555b5294f2b7f20fe8460a7dfb94cec05406ed7367f2376367b88d63d8c7cR43-R83],
> while it was once doing that as the last option.
> We tried to update WSS4J from 3.0.5 to 3.0.6 in JBoss EAP 8.1 and we're
> hitting security exceptions due to missing permissions on tests running with
> the Security Manager enabled:
> {code:java}
> ...
> ERROR [stderr] (default task-1) java.security.AccessControlException:
> WFSM000001: Permission check failed (permission "("java.io.FilePermission"
> "/home/jenkins/workspace/testsuite/integration/ws/xcatalog" "read")" in code
> source
> "(vfs:/content/jaxws-samples-wsse-policy-trust-onbehalfof.war/WEB-INF/classes
> <no signer certificates>)" of "ModuleClassLoader for Module
> "deployment.jaxws-samples-wsse-policy-trust-onbehalfof.war" from Service
> Module Loader")
> ...{code}
> Deployments break unless such permissions are added to them by the user,
> which configures a regression.
> The change landed in 4.0.2 and in 3.0.6 (at least, I didn't check other tags).
> One argument could be about the Security Manager APIs going to be removed,
> but in maintenance branches like 3.0.x this issue is currently blocking the
> WSS4J upgrade that would resolve many CVEs.
> The {{Loader}} class uses to call Security Manager APIs - i.e.
> {{doPrivileged()-}} already in some cases.
> Would it be a viable option to fix by wrapping the meaningful code blocks,
> like the file system access in this very case, into {{doPrivileged()}} calls,
> at least for 3.0.6+?
--
This message was sent by Atlassian Jira
(v8.20.10#820010)
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]