From 23ec23948e6946e6f62317c0e530ef8049bb5301 Mon Sep 17 00:00:00 2001 From: CSTRSK Date: Sun, 9 Aug 2026 09:43:49 +0000 Subject: [PATCH] test-cases: add CWE-215 (java) --- docs/VULNERABILITY_CATALOG.md | 11 +++-- vulns/VULNERABILITY_CATALOG.json | 34 ++++++++++++-- vulns/java/cwe-215-java.java | 78 ++++++++++++++++++++++++++++++++ 3 files changed, 114 insertions(+), 9 deletions(-) create mode 100644 vulns/java/cwe-215-java.java diff --git a/docs/VULNERABILITY_CATALOG.md b/docs/VULNERABILITY_CATALOG.md index 5763d34..9b0367d 100644 --- a/docs/VULNERABILITY_CATALOG.md +++ b/docs/VULNERABILITY_CATALOG.md @@ -7,12 +7,12 @@ from each file's header comment, so this page cannot drift from the source. ## Totals -- **Test cases:** 62 -- **Expected detections:** 62 -- **`VULNERABLE:` markers:** 123 (individual lines a scanner should flag) -- **`SAFE:` markers:** 73 (lines a scanner must not flag — the false-positive control group) +- **Test cases:** 63 +- **Expected detections:** 63 +- **`VULNERABLE:` markers:** 125 (individual lines a scanner should flag) +- **`SAFE:` markers:** 75 (lines a scanner must not flag — the false-positive control group) - **Languages:** 8 — dotenv, go, java, javascript, json, python, ruby, text -- **CWE categories:** 46 — CWE-20, CWE-22, CWE-78, CWE-79, CWE-89, CWE-90, CWE-95, CWE-113, CWE-117, CWE-190, CWE-201, CWE-209, CWE-256, CWE-295, CWE-321, CWE-327, CWE-330, CWE-338, CWE-346, CWE-347, CWE-352, CWE-362, CWE-377, CWE-384, CWE-489, CWE-502, CWE-506, CWE-532, CWE-601, CWE-611, CWE-614, CWE-639, CWE-643, CWE-681, CWE-759, CWE-798, CWE-862, CWE-915, CWE-918, CWE-942, CWE-943, CWE-1236, CWE-1321, CWE-1333, CWE-1336, CWE-1357 +- **CWE categories:** 47 — CWE-20, CWE-22, CWE-78, CWE-79, CWE-89, CWE-90, CWE-95, CWE-113, CWE-117, CWE-190, CWE-201, CWE-209, CWE-215, CWE-256, CWE-295, CWE-321, CWE-327, CWE-330, CWE-338, CWE-346, CWE-347, CWE-352, CWE-362, CWE-377, CWE-384, CWE-489, CWE-502, CWE-506, CWE-532, CWE-601, CWE-611, CWE-614, CWE-639, CWE-643, CWE-681, CWE-759, CWE-798, CWE-862, CWE-915, CWE-918, CWE-942, CWE-943, CWE-1236, CWE-1321, CWE-1333, CWE-1336, CWE-1357 ## How coverage is scored @@ -36,6 +36,7 @@ counts as a detection. See `docs/SCANNER_INTEGRATION.md`. | Test case | File | CWE | Severity | Expected | Markers | |---|---|---|---|---|---| | Insecure deserialisation via ObjectInputStream | [`deserialization-object-input-stream.java`](../vulns/java/deserialization-object-input-stream.java) | CWE-502 | critical | yes | 2 vuln / 2 safe | +| Sensitive data exposure via debug logging | [`cwe-215-java.java`](../vulns/java/cwe-215-java.java) | CWE-215 | high | yes | 2 vuln / 2 safe | | SQL injection via Statement string concatenation | [`sqli-statement-concat.java`](../vulns/java/sqli-statement-concat.java) | CWE-89 | critical | yes | 2 vuln / 1 safe | | Reflected XSS via HttpServletResponse writer | [`xss-response-writer.java`](../vulns/java/xss-response-writer.java) | CWE-79 | high | yes | 2 vuln / 2 safe | | XXE via unconfigured DocumentBuilderFactory | [`xxe-document-builder.java`](../vulns/java/xxe-document-builder.java) | CWE-611 | high | yes | 2 vuln / 1 safe | diff --git a/vulns/VULNERABILITY_CATALOG.json b/vulns/VULNERABILITY_CATALOG.json index 153fdaf..a163829 100644 --- a/vulns/VULNERABILITY_CATALOG.json +++ b/vulns/VULNERABILITY_CATALOG.json @@ -2,10 +2,10 @@ "schema": "threatcrush-testbed-catalog/1", "note": "Generated by scripts/generate-catalog.py \u2014 do not edit by hand.", "totals": { - "test_cases": 62, - "expected_detections": 62, - "vulnerable_markers": 123, - "safe_markers": 73, + "test_cases": 63, + "expected_detections": 63, + "vulnerable_markers": 125, + "safe_markers": 75, "languages": [ "dotenv", "go", @@ -38,6 +38,7 @@ "CWE-190", "CWE-201", "CWE-209", + "CWE-215", "CWE-256", "CWE-295", "CWE-321", @@ -175,6 +176,31 @@ 56 ] }, + { + "id": "java-information-exposure-debug-log", + "file": "vulns/java/cwe-215-java.java", + "title": "Sensitive data exposure via debug logging", + "category": "java", + "language": "java", + "cwe": "CWE-215", + "cwes": [ + "CWE-215" + ], + "severity": "high", + "expected_detection": true, + "description": "A user-controlled request parameter (e.g., a session token or", + "detection_target": "Logger.debug called with a sensitive request parameter", + "safe_guard": "Every payload is behind the always-false NEVER_RUN constant and", + "attribution": "line", + "vulnerable_lines": [ + 36, + 44 + ], + "safe_lines": [ + 57, + 73 + ] + }, { "id": "java-deserialization-object-input-stream", "file": "vulns/java/deserialization-object-input-stream.java", diff --git a/vulns/java/cwe-215-java.java b/vulns/java/cwe-215-java.java new file mode 100644 index 0000000..72dffb5 --- /dev/null +++ b/vulns/java/cwe-215-java.java @@ -0,0 +1,78 @@ +/** + * @id java-information-exposure-debug-log + * @test-case Sensitive data exposure via debug logging + * @cwe CWE-215 + * @severity high + * @language java + * @expected-detection true + * @description A user-controlled request parameter (e.g., a session token or + * password reset token) is logged in plaintext via a debug logger. + * This exposes sensitive information to anyone with access to the + * application logs, violating CWE-215 (Insertion of Sensitive + * Information Into Debugging Code). The vulnerable code logs the + * full token value without any redaction or masking. + * @safe-guard Every payload is behind the always-false NEVER_RUN constant and + * the repository has no Java build file, so nothing is compiled. + * No real credentials or tokens are included in this file. + * @detection-target Logger.debug called with a sensitive request parameter + * (e.g., token, password, session ID) without masking. + * + * NEVER RUN IN PRODUCTION — intentional test case for scanner validation. + */ +package vulns.java; + +import org.slf4j.Logger; +import org.slf4j.LoggerFactory; +import javax.servlet.http.HttpServletRequest; + +public class InformationExposureDebugLog { + + private static final boolean NEVER_RUN = false; + private static final Logger logger = LoggerFactory.getLogger(InformationExposureDebugLog.class); + + public void logTokenVulnerable(HttpServletRequest req) { + if (NEVER_RUN) { + String token = req.getParameter("reset_token"); // SOURCE + // VULNERABLE: CWE-215 - sensitive token logged in plaintext + logger.debug("Password reset token for user: {}", token); + } + } + + public void logSessionVulnerable(HttpServletRequest req) { + if (NEVER_RUN) { + String sessionId = req.getHeader("Authorization"); // SOURCE + // VULNERABLE: CWE-215 - session credential logged in plaintext + logger.debug("User session token: {}", sessionId); + } + } + + /** + * Safe counterpart — the scanner should NOT flag this. + * + * @expected-detection false + */ + public void logTokenSafe(HttpServletRequest req) { + if (NEVER_RUN) { + String token = req.getParameter("reset_token"); + // SAFE: token is masked before logging + String maskedToken = token != null && token.length() > 4 + ? token.substring(0, 4) + "****" + : "****"; + logger.debug("Password reset token for user: {}", maskedToken); + } + } + + /** + * Safe counterpart — the scanner should NOT flag this. + * + * @expected-detection false + */ + public void logSessionSafe(HttpServletRequest req) { + if (NEVER_RUN) { + String sessionId = req.getHeader("Authorization"); + // SAFE: only a boolean flag is logged, not the actual token + boolean hasSession = sessionId != null && !sessionId.isEmpty(); + logger.debug("User session present: {}", hasSession); + } + } +} \ No newline at end of file