[ 
https://issues.apache.org/jira/browse/WSS-733?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18125100#comment-18125100
 ] 

Fabio Burzigotti commented on WSS-733:
--------------------------------------

[~coheigea] PR sent, see [https://github.com/apache/ws-wss4j/pull/744] - it 
passes our tests.

> Loader.loadInputStream() unprivileged access to FileSystem
> ----------------------------------------------------------
>
>                 Key: WSS-733
>                 URL: https://issues.apache.org/jira/browse/WSS-733
>             Project: WSS4J
>          Issue Type: Bug
>          Components: WSS4J Core
>    Affects Versions: 3.0.6, 4.0.2
>            Reporter: Fabio Burzigotti
>            Assignee: Colm O hEigeartaigh
>            Priority: Critical
>             Fix For: 3.0.7
>
>
> Loader.loadInputStream [was recently modified to look into the file system 
> first|https://github.com/apache/ws-wss4j/commit/6c3257a83caa9c11e4af4af6b675e26f59b921f5#diff-92c555b5294f2b7f20fe8460a7dfb94cec05406ed7367f2376367b88d63d8c7cR43-R83],
>  while it was once doing that as the last option.
> We tried to update WSS4J from 3.0.5 to 3.0.6 in JBoss EAP 8.1 and we're 
> hitting security exceptions due to missing permissions on tests running with 
> the Security Manager enabled:
> {code:java}
>  ...
> ERROR [stderr] (default task-1) java.security.AccessControlException: 
> WFSM000001: Permission check failed (permission "("java.io.FilePermission" 
> "/home/jenkins/workspace/testsuite/integration/ws/xcatalog" "read")" in code 
> source 
> "(vfs:/content/jaxws-samples-wsse-policy-trust-onbehalfof.war/WEB-INF/classes 
> <no signer certificates>)" of "ModuleClassLoader for Module 
> "deployment.jaxws-samples-wsse-policy-trust-onbehalfof.war" from Service 
> Module Loader")
> ...{code}
> Deployments break unless such permissions are added to them by the user, 
> which configures a regression.
> The change landed in 4.0.2 and in 3.0.6 (at least, I didn't check other tags).
> One argument could be about the Security Manager APIs going to be removed, 
> but in maintenance branches like 3.0.x this issue is currently blocking the 
> WSS4J upgrade that would resolve many CVEs.
> The {{Loader}} class uses to call Security Manager APIs - i.e. 
> {{doPrivileged()-}} already in some cases. 
> Would it be a viable option to fix by wrapping the meaningful code blocks, 
> like the file system access in this very case, into {{doPrivileged()}} calls, 
> at least for 3.0.6+?



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to