Fortify : Resource Injection

Viewed 1621

I have the following code and I am getting the Resource injection issue at the copyMessages().
I don't know how to fix the issue?

Abstract: Attackers are able to control the resource identifier argument to copyMessages() at MailboxProcessorServiceImpl.java line 77, which could enable them to access or modify otherwise protected system resources. 
FileName: 
LineNo: 77
Sink: javax.mail.Folder.copyMessages() 
Folder inboxFolder = mailUtil.openFolder(store, "INBOX");
        Folder processedFolder = mailUtil.openFolder(store, "Processed");
        try {

            Flags flaggedFlags = new Flags(Flags.Flag.FLAGGED);
            Flags deletedFlags = new Flags(Flags.Flag.DELETED);
            Message[] msgs = inboxFolder.search(new FlagTerm(flaggedFlags, false));
            log.info("# of new Emails received: " + Integer.toString(msgs.length));
            if (msgs.length > 0) {
                for (Message msg : msgs) {
                    log.info(msg.getSubject());
                    Map<String, InputStream> mis = getAttachments(msg);
                    if (!CollectionUtils.isEmpty(mis))
                        saveAndProcessAttachment(mis, msg);

                    Message[] processedMsgs = { msg };
                    if (processedMsgs.length > 0) {
                        inboxFolder.copyMessages(processedMsgs, processedFolder);
                    }
                    msg.setFlags(deletedFlags, true);
                }
            }
            inboxFolder.close(true);
            processedFolder.close();
2 Answers

I think the resource injection issue is reported because of the parameter 'store'. It is going to determine the resource location where your processedMsg will be stored. And it seems that this parameter is taken from not trusted source. Maybe from a request parameter?

So imagine someone give you the 'store' parameter like "../../somewere". User can use whatever rest client to do it, not only your front end application that would never allow it.

  • Will this go to parent of the parent directory and put the message to '/somewere/Processed'?
  • Can this feature overwrite some of the important system files on behalf of the user you use to run the server?
  • If the 'store' is expected to contain a string that user can easily guess, can he just trick it giving wrong 'store' as a parameter? For example if store is actually the username. (You can tell some example what 'store' contains.)

Typically you should either take the location from a trusted source, or to sanitize the input parameter and tell the scanning tool you have sanitized it. For example allowing only alphanumeric characters.

Was this helpfull?

I'm not sure I understand that complaint but perhaps it's noting that the attacker could send an arbitrary message which would then get copied to the processedFolder? If the message is large, it could exhaust resources.

Related