False positive - Java - Server-side request forgery - When type converted to `File`
- 主要語言
- CodeQL
- 星號
- 10.1k
- 分支
- 2.1k
- 平均合併
- 2 天 15 小時
- 30 天內合併 PR
- 141
描述
**Description of the false positive**
If a `URI` or `URL` is created from a `File` it isn't a valid source of SSRF. This is because, AFAIK, opening a stream from a file will never create a socket request.
`new File("untrusted-user-input.txt").toURI().toURL().openStream()`
**Code samples or links to source code**
https://github.com/keycloak/keycloak/blob/0bfadacffd1112e6fa6fdce5b6662b08aeb15d79/services/src/main/java/org/keycloak/theme/FolderTheme.java#L101-L101
**URL to the alert on GitHub code scanning (optional)**
https://github.com/Chainguard-Wolfi-Bites-Back/keycloak__keycloak/security/code-scanning/18
**Reasonable Fix**
It should be simple to add any type conversion to a `File` as a simple sanitizer.
貢獻指南
研究方向
Start with the linked Keycloak example in services/src/main/java/org/keycloak/theme/FolderTheme.java at line 101 and inspect the linked code-scanning alert. Then locate the CodeQL Java SSRF query and its sanitizer tests. Done means a URI or URL derived from a File is no longer reported as an SSRF source.
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- java
- 領域
- security
- Issue 類型
- 缺陷
- 難度
- 4/5
- 預估耗時
- 3-5 天
- 活躍度
- 停滯
- 描述清晰度
- 基本清楚
- 新手友好度
- 35/100