Recursion in Util.java. I suspect that this will lead to issues passing a Google Tier2 CASA
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 2/5
- Tempo stimato
- 1-3 ore
- Idoneità per principianti
- 35/100
- Tipo di issue
- Bug
- Chiarezza
- Abbastanza chiara
- Stato di attività
- Ferma
- Stack tecnologico
- android, java
- Ambito
- mobile-dev, security
Direzione di ricerca
Inizia dal blocco catch di isDebuggableApp indicato in test-app/app/src/main/java/com/tns/Util.java, quindi esamina il punto di ingresso isDebuggable() in test-app/runtime/src/main/java/com/tns/Runtime.java. Conferma che il percorso catch non possa ricorsivamente richiamarsi e verifica che il comportamento risultante soddisfi il comportamento previsto e affronti la preoccupazione relativa alla scansione segnalata.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
Environment
Provide version numbers for the following components (information can be retrieved by running tns info in your project folder or by inspecting the package.json of the project):
✔ Getting NativeScript components versions information...
✔ Component nativescript has 8.5.3 version and is up to date.
✔ Component @nativescript/core has 8.5.9 version and is up to date.
✔ Component @nativescript/ios has 8.5.2 version and is up to date.
✔ Component @nativescript/android has 8.5.2 version and is up to date.
Describe the bug
Hello together, I am currently preparing for a Tier2 CASA from Google. As I do have to provide Source Code scans using FluidAttacks and it detected a vulnerability in this context of printStackTrace I found the following issue.
public static boolean isDebuggableApp(Context context) {
int flags;
try {
flags = context.getPackageManager().getPackageInfo(context.getPackageName(), 0).applicationInfo.flags;
} catch (NameNotFoundException e) {
flags = 0;
if (Util.isDebuggableApp(context)) {
e.printStackTrace();
}
}
boolean isDebuggableApp = ((flags & ApplicationInfo.FLAG_DEBUGGABLE) != 0);
return isDebuggableApp;
}
It is clear that printStackTrace() is only called in debug mode. However, I consider telling the guys at Google that this is save code as no good idea as it results in a recursion in the catch block. I would suspect that the e.printStackTrace(); in the catch block is actually never called, hence would it not make sense to completly remove it? I have also seen that the runtime provides
a check for isDebuggableApp. Maybe a save alternative would be to just call com.tns.Runtime.isDebuggable() ?
I do not know the inner workings good enough to know if the runtime always exists at that point. Please consider it as just an idea.
Expected behavior
Catch should not run into a rekursion
Additional context
https://gitlab.com/fluidattacks/universe/-/issues/10406
Currently I am seeing lots of issues in FluidAttacks indirectly referencing this code. Below output is just an example. To my understanding this is a false positive as printStackTrace is not called for production builds. However, also in production builds the recursion would exist to my understanding.
234. Technical information leak - Stacktrace,CWE-209,The error stacktrace can be printed in OWASP/app/src/debug/java/com/tns/ErrorReport.java,CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R,https://docs.fluidattacks.com/criteria/vulnerabilities/234,skims,SAST,92,"
82 | final int version = Build.VERSION.SDK_INT;
83 | if (version >= 23) {
84 | try {
85 | // Necessary to work around compile errors with compileSdk 22 and lower
86 | Method checkSelfPermissionMethod;
87 | try {
88 | checkSelfPermissionMethod = ActivityCompat.class.getMethod(""checkSelfPermission"", Context.class, Stri
89 | } catch (NoSuchMethodException e) {
90 | // method wasn't found, so there is no need to handle permissions explicitly
91 | if (Util.isDebuggableApp(activity)) {
> 92 | e.printStackTrace();
93 | }
94 | return;
95 | }
96 |
97 | int permission = (int) checkSelfPermissionMethod.invoke(null, activity, Manifest.permission.WRITE_EXTERNA
98 |
99 | if (permission != PackageManager.PERMISSION_GRANTED) {
100 | // We don't have permission so prompt the user
101 | Method requestPermissionsMethod = ActivityCompat.class.getMethod(""requestPermissions"", Activity.class
102 |
^ Col 0
",java.java_info_leak_stacktrace
- Lingua principale
- C++
- Stelle
- 563
- Fork
- 144
- Merge medio
- 10h 46m
- PR unite (30g)
- 14
Guida per i contributori
Apri la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di NativeScript/android
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 38/100
NativeScript/android#2039 · 1 commento ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 48/100
NativeScript/android#2024 ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 20/100
NativeScript/android#2020 ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 42/100
NativeScript/android#2019 ·
-
Difficoltà 4/5 3-5 giorni Idoneità per principianti 55/100
NativeScript/android#1986 ·
Tutte le issue di NativeScript/android
Issue simili
-
[BUG] Apertabug
Difficoltà 2/5 1-3 ore Idoneità per principianti 85/100
eunomia-bpf/llvmbpf#51 · 1 commento ·
-
status:needs-triage
Difficoltà 2/5 1-3 ore Idoneità per principianti 78/100
PX4/PX4-Autopilot#28776 ·
-
Website Doc Typo Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 92/100
-
Difficoltà 1/5 1-3 ore Idoneità per principianti 92/100
autowarefoundation/autoware_universe#13413 ·
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 88/100