ppkarwasz opened a new issue, #4334:
URL: https://github.com/apache/logging-log4j2/issues/4334
`ThrowableInvertedPropertyRendererFactory#extractThrowingMethod` returns
`Throwables.getRootCause(throwable).getStackTrace()[0]` without checking the
array length, whereas `ThrowablePropertyRendererFactory#extractThrowingMethod`
guards against a `null` or empty stack trace and returns `null`. Rendering
`%rEx{short.className}`, `%rEx{short.methodName}`, `%rEx{short.lineNumber}` or
`%rEx{short.fileName}` for an exception whose root cause has an empty stack
trace therefore throws `ArrayIndexOutOfBoundsException`; with the default
`ignoreExceptions="true"` the appender drops the event and reports the error to
the status logger, with `ignoreExceptions="false"` an
`AppenderLoggingException` propagates to the caller. `%ex{short.*}` and the
plain `%rEx` render the same event fine.
An empty stack trace is legal per the `Throwable` contract
(`setStackTrace(new StackTraceElement[0])`, exceptions created with
`writableStackTrace = false`) and is also produced by HotSpot's default
`-XX:+OmitStackTraceInFastThrow` for implicit exceptions thrown repeatedly at
the same site. The code was introduced with the stack trace rendering rework in
2.25.0 (#2691, #3045) and is identical on `main`. This issue originates from a
private security report classified as a bug (**not** a vulnerability).
Fix: mirror the guard of the non-inverted factory in
`ThrowableInvertedPropertyRendererFactory`, and add a test rendering all four
`short.*` properties with `%rEx` for a wrapped exception whose root cause has
an empty stack trace.
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]