mirror of
https://github.com/Alfresco/alfresco-transform-core.git
synced 2026-09-16 18:12:54 +00:00
[ACS-11995] fix codeql path and command injection (#1292)
This commit is contained in:
+4
@@ -120,6 +120,10 @@ public abstract class AbstractMetadataExtractsIT
|
|||||||
|
|
||||||
private Map<String, Serializable> readExpectedMetadata(String filename, File actualMetadataFile) throws IOException
|
private Map<String, Serializable> readExpectedMetadata(String filename, File actualMetadataFile) throws IOException
|
||||||
{
|
{
|
||||||
|
if (filename.contains("..") || filename.contains("/") || filename.contains("\\"))
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException("Invalid expected metadata filename: " + filename);
|
||||||
|
}
|
||||||
try (InputStream inputStream = this.getClass().getClassLoader().getResourceAsStream(filename))
|
try (InputStream inputStream = this.getClass().getClassLoader().getResourceAsStream(filename))
|
||||||
{
|
{
|
||||||
if (inputStream == null)
|
if (inputStream == null)
|
||||||
|
|||||||
@@ -667,11 +667,7 @@ public class RuntimeExec
|
|||||||
{
|
{
|
||||||
String key = entry.getKey();
|
String key = entry.getKey();
|
||||||
String value = entry.getValue() == null ? "" : entry.getValue();
|
String value = entry.getValue() == null ? "" : entry.getValue();
|
||||||
if (value.contains("\n") || value.contains("\r") || value.contains("\0"))
|
validateCommandPropertyValue(key, value);
|
||||||
{
|
|
||||||
throw new IllegalArgumentException(
|
|
||||||
"Command property '" + key + "' contains an illegal character");
|
|
||||||
}
|
|
||||||
// progressively replace the property in the command
|
// progressively replace the property in the command
|
||||||
key = (VAR_OPEN + key + VAR_CLOSE);
|
key = (VAR_OPEN + key + VAR_CLOSE);
|
||||||
int index = sb.indexOf(key);
|
int index = sb.indexOf(key);
|
||||||
@@ -704,6 +700,55 @@ public class RuntimeExec
|
|||||||
return adjustedCommandElements.toArray(new String[0]);
|
return adjustedCommandElements.toArray(new String[0]);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
private void validateCommandPropertyValue(String key, String value)
|
||||||
|
{
|
||||||
|
if (value.contains("\n") || value.contains("\r") || value.contains("\0"))
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Command property '" + key + "' contains an illegal character");
|
||||||
|
}
|
||||||
|
|
||||||
|
if ("source".equals(key) || "target".equals(key))
|
||||||
|
{
|
||||||
|
validatePathProperty(key, value);
|
||||||
|
}
|
||||||
|
else if ("sourceMimetype".equals(key) || "targetMimetype".equals(key))
|
||||||
|
{
|
||||||
|
validateMimetypeProperty(key, value);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void validatePathProperty(String key, String value)
|
||||||
|
{
|
||||||
|
if (value.isBlank())
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException("Command property '" + key + "' must not be blank");
|
||||||
|
}
|
||||||
|
|
||||||
|
// Allow quotes/backticks in paths; this class executes via Runtime.exec(String[]) (no shell parsing)
|
||||||
|
|
||||||
|
File file = new File(value);
|
||||||
|
if (!file.isAbsolute())
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Command property '" + key + "' must be an absolute path");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
private void validateMimetypeProperty(String key, String value)
|
||||||
|
{
|
||||||
|
if (value.isBlank())
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException("Command property '" + key + "' must not be blank");
|
||||||
|
}
|
||||||
|
|
||||||
|
if (!value.matches("^[a-zA-Z0-9!#$&^_.+-]+/[a-zA-Z0-9!#$&^_.+-]+$"))
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException(
|
||||||
|
"Command property '" + key + "' is not a valid mimetype");
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Object to carry the results of an execution to the caller.
|
* Object to carry the results of an execution to the caller.
|
||||||
*
|
*
|
||||||
|
|||||||
+4
@@ -119,6 +119,10 @@ public abstract class AbstractMetadataExtractsIT
|
|||||||
|
|
||||||
private Map<String, Serializable> readExpectedMetadata(String filename, File actualMetadataFile) throws IOException
|
private Map<String, Serializable> readExpectedMetadata(String filename, File actualMetadataFile) throws IOException
|
||||||
{
|
{
|
||||||
|
if (filename.contains("..") || filename.contains("/") || filename.contains("\\"))
|
||||||
|
{
|
||||||
|
throw new IllegalArgumentException("Invalid expected metadata filename: " + filename);
|
||||||
|
}
|
||||||
try (InputStream inputStream = this.getClass().getClassLoader().getResourceAsStream(filename))
|
try (InputStream inputStream = this.getClass().getClassLoader().getResourceAsStream(filename))
|
||||||
{
|
{
|
||||||
if (inputStream == null)
|
if (inputStream == null)
|
||||||
|
|||||||
Reference in New Issue
Block a user