ppkarwasz opened a new issue, #4334:
URL: https://github.com/apache/logging-log4j2/issues/4334

   `ThrowableInvertedPropertyRendererFactory#extractThrowingMethod` returns 
`Throwables.getRootCause(throwable).getStackTrace()[0]` without checking the 
array length, whereas `ThrowablePropertyRendererFactory#extractThrowingMethod` 
guards against a `null` or empty stack trace and returns `null`. Rendering 
`%rEx{short.className}`, `%rEx{short.methodName}`, `%rEx{short.lineNumber}` or 
`%rEx{short.fileName}` for an exception whose root cause has an empty stack 
trace therefore throws `ArrayIndexOutOfBoundsException`; with the default 
`ignoreExceptions="true"` the appender drops the event and reports the error to 
the status logger, with `ignoreExceptions="false"` an 
`AppenderLoggingException` propagates to the caller. `%ex{short.*}` and the 
plain `%rEx` render the same event fine.
   
   An empty stack trace is legal per the `Throwable` contract 
(`setStackTrace(new StackTraceElement[0])`, exceptions created with 
`writableStackTrace = false`) and is also produced by HotSpot's default 
`-XX:+OmitStackTraceInFastThrow` for implicit exceptions thrown repeatedly at 
the same site. The code was introduced with the stack trace rendering rework in 
2.25.0 (#2691, #3045) and is identical on `main`. This issue originates from a 
private security report classified as a bug (**not** a vulnerability).
   
   Fix: mirror the guard of the non-inverted factory in 
`ThrowableInvertedPropertyRendererFactory`, and add a test rendering all four 
`short.*` properties with `%rEx` for a wrapped exception whose root cause has 
an empty stack trace.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to