Tim Scheckenbach created JXPATH-206:
---------------------------------------
Summary: apache-commons-jxpath: stop JXPathFuzzer from reading
files and opening connections
Key: JXPATH-206
URL: https://issues.apache.org/jira/browse/JXPATH-206
Project: Commons JXPath
Issue Type: Bug
Affects Versions: 1.4.0
Reporter: Tim Scheckenbach
Attachments: Archive.zip
{{JXPathFuzzer}} parses the input itself, before JXPath is involved:
{code:java}
doc = builder.parse(new InputSource(new
StringReader(data.consumeString(2000))));
{code}
The {{DocumentBuilderFactory}} above it is unconfigured, so a DOCTYPE in the
input makes the parser open the file or URL it names.
The seed corpus shipped with the fuzzer contains XHTML doctypes, multiple files
mention {{www.w3.org}}, and a plain run would contact that host and stop with
this error:
{code}
$ python3 infra/helper.py run_fuzzer apache-commons-jxpath JXPathFuzzer --
-runs=3000
== Java Exception: com.code_intelligence.jazzer.api.FuzzerSecurityIssueMedium:
Server Side Request Forgery (SSRF)
Attempted connection to: www.w3.org:80
{code}
h2. Patch
{code:java}
factory.setFeature("http://xml.org/sax/features/external-general-entities",
false);
factory.setFeature("http://xml.org/sax/features/external-parameter-entities",
false);
factory.setFeature("http://apache.org/xml/features/nonvalidating/load-external-dtd",
false);
factory.setXIncludeAware(false);
{code}
The same run then finishes.
It also fixes the two open testcases, attached.
These two crashes are related to this issue that is marked as fixed but still
exists (https://issues.oss-fuzz.com/issues/42525841).
Both stack traces end at {{JXPathFuzzer.java:48}} inside the JDK's XML parser.
So they crash before any JXPath code would be executed:
Download the attached Archive.zip and unzip the crash reports contained in it.
{code}
export DOCKER_DEFAULT_PLATFORM=linux/amd64 # if on mac
git clone https://github.com/google/oss-fuzz.git
cd oss-fuzz
python3 infra/helper.py build_image apache-commons-jxpath
python3 infra/helper.py build_fuzzers --sanitizer address apache-commons-jxpath
cp <unzipped Archive.zip crashes> .
python3 infra/helper.py reproduce apache-commons-jxpath JXPathFuzzer
crash-063b9cde5d2bb9ecf27962e885b4da22756bb642
python3 infra/helper.py reproduce apache-commons-jxpath JXPathFuzzer
crash-00aa313fb7828be750fc6c4372b976283e6f125e
{code}
Found by the CISPA Fandango-Team while triaging OSS-Fuzz findings for
apache-commons-jxpath.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)