Skip to content

Commit

Permalink
feat(java): custom MessageDigest class (#196)
Browse files Browse the repository at this point in the history
Co-authored-by: Cédric Fabianski <[email protected]>
  • Loading branch information
elsapet and cfabianski authored Jan 29, 2024
1 parent 7023b4e commit 1fb29e9
Show file tree
Hide file tree
Showing 3 changed files with 60 additions and 0 deletions.
29 changes: 29 additions & 0 deletions rules/java/lang/custom_message_digest_class.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,29 @@
patterns:
- pattern: |
class $<...>$<_> extends $<MESSAGE_DIGEST_CLASS> {};
filters:
- variable: MESSAGE_DIGEST_CLASS
regex: \A(java\.security\.)?MessageDigest\z
languages:
- java
severity: warning
metadata:
description: "Custom implementation of a Digest class detected."
remediation_message: |
## Description
Implementing a custom Digest class manually is not advised as the process could lead to errors.
Instead use a standard Digest algorithm such as SHA-256 or SHA-512.
## Remediations
❌ Do not implement a custom Digest class by hand
✅ Choose a standard Digest algorithm as SHA-256, SHA-384, SHA-512, or SHA-512/256.
## Resources
- [Java MessageDigest class](https://docs.oracle.com/en/java/javase/20/docs/api/java.base/java/security/MessageDigest.html)
cwe_id:
- 327
id: java_lang_custom_message_digest_class
documentation_url: https://docs.bearer.com/reference/rules/java_lang_custom_message_digest_class
18 changes: 18 additions & 0 deletions tests/java/lang/custom_message_digest_class/test.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,18 @@
const {
createNewInvoker,
getEnvironment,
} = require("../../../helper.js")
const { ruleId, ruleFile, testBase } = getEnvironment(__dirname)

describe(ruleId, () => {
const invoke = createNewInvoker(ruleId, ruleFile, testBase)

test("custom_message_digest_class", () => {
const testCase = "main.java"

const results = invoke(testCase)

expect(results.Missing).toEqual([])
expect(results.Extra).toEqual([])
})
})
13 changes: 13 additions & 0 deletions tests/java/lang/custom_message_digest_class/testdata/main.java
Original file line number Diff line number Diff line change
@@ -0,0 +1,13 @@
package crypto;

import java.security.MessageDigest;

// bearer:expected java_lang_custom_message_digest_class
public class CustomMessageDigest extends MessageDigest {
// some custom implementation process
}

// bearer:expected java_lang_custom_message_digest_class
class MyOtherCustomMessageDigest extends java.security.MessageDigest {
// some custom implementation process
}

0 comments on commit 1fb29e9

Please sign in to comment.