| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Introduce AdvancedConfigServlet with three taint vulnerabilities whose sinks (cn.hutool.* APIs) are modeled only by the javasecurity-advanced library config, not the base/Enterprise javasecurity config: - S2076 OS command injection via RuntimeUtil.exec(String...) - S2083 path traversal via FileUtil.readUtf8String(String) - S2083 path traversal via FileUtil.del(String) Source is HttpServletRequest.getParameter (base-modeled), so these issues isolate the detection value added by the advanced library config. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
Sorry, something went wrong.
| protected void doGet(HttpServletRequest request, HttpServletResponse response) | ||
| throws ServletException, IOException { | ||
| String cmd = request.getParameter("cmd"); | ||
| RuntimeUtil.exec(cmd); // advanced-only sink |
| protected void readFile(HttpServletRequest request, HttpServletResponse response) | ||
| throws IOException { | ||
| String path = request.getParameter("path"); | ||
| String content = FileUtil.readUtf8String(path); // advanced-only sink |
| */ | ||
| protected void deleteFile(HttpServletRequest request) { | ||
| String victim = request.getParameter("file"); | ||
| FileUtil.del(victim); // advanced-only sink |
| protected void readFile(HttpServletRequest request, HttpServletResponse response) | ||
| throws IOException { | ||
| String path = request.getParameter("path"); | ||
| String content = FileUtil.readUtf8String(path); // advanced-only sink |
| */ | ||
| protected void deleteFile(HttpServletRequest request) { | ||
| String victim = request.getParameter("file"); | ||
| FileUtil.del(victim); // advanced-only sink |
| Back | FazBrowse Home | New Git URL |
What
Adds AdvancedConfigServlet with three taint vulnerabilities whose sinks are modeled only by the javasecurity-advanced library config — not the base/Enterprise javasecurity config.
Why
Source is HttpServletRequest.getParameter (modeled by the base config). The sinks are Hutool (cn.hutool.*) APIs that exist in javasecurity-advanced but are absent from the base config:
Isolates the detection value of the advanced library config.
Changes
Compiles clean. Vulnerabilities are intentional demo payload.
🤖 Generated with Claude Code