apache / apache/grails-core

Veracode security scan finds Medium flaw in SoftServiceLoader.java

Open
#14,421 0 comments 0 reactions 0 assignees View on GitHub
relates-to: gorm
Dominant language
Groovy
Stars
2.9k
Forks
975
Avg merge
1d 22h
Merged PRs (30d)
92

Description

### Task List

Veracode scan finds a medium security flaw in this file for the function ServiceDefinition on line / around 261.

There is little verification of the strings passed.

This is a static scan which just looks at the code itself.

### Environment Information

- **Operating System**: TOD
- **GORM Version:** TODO
- **Grails Version (if using Grails):** TODO
- **JDK Version:** TODO

### Example Application

Information from the Veracode scan:

A call uses reflection in an unsafe manner. An attacker can specify the class name to be instantiated, which may create unexpected control flow paths through the application. Depending on how reflection is being used, the attack vector may allow the attacker to bypass security checks or otherwise cause the application to behave in an unexpected manner. Even if the object does not implement the specified interface and a ClassCastException is thrown, the constructor of the untrusted class name will have already executed.

Veracode recommends: Validate the class name against a combination of white and black lists to ensure that only expected behavior is produced.

Contributor guide

Open the contributing guide

Research direction

Start by reading SoftServiceLoader.java around the ServiceDefinition function near line 261 and trace where the class name originates and is instantiated. Compare the current handling with Veracode's reflection warning; done means the input is appropriately constrained and the security scan no longer reports this flaw.

Written by the indexing model from the issue text.

Assessment

Tech stack
groovy, java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
30/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.