From a07ac702e04667962365704668cf1c553ff4eb4a Mon Sep 17 00:00:00 2001 From: Dmitry Avdeev Date: Fri, 12 Jul 2019 19:16:40 +0300 Subject: [PATCH] IDEA-216621 xslt debugger plugin misconfiguration allows arbitrary file read over network introduced access token for eval() call GitOrigin-RevId: ddcbbfed9b16a8c7e2d09b6c3896aaf321325dc3 --- .../rt/engine/remote/DebuggerServer.java | 10 ++++---- .../xslt-debugger/engine/lib/rmi-stubs.jar | Bin 28854 -> 28354 bytes .../rt/engine/remote/RemoteDebugger.java | 4 ++-- .../engine/remote/RemoteDebuggerClient.java | 22 ++++++++++-------- .../rt/engine/remote/RemoteFrameImpl.java | 15 +++++++----- .../xsltDebugger/DebugProcessListener.java | 6 +++-- .../xsltDebugger/DebuggerConnector.java | 6 +++-- .../xsltDebugger/XsltDebuggerExtension.java | 8 ++++++- 8 files changed, 44 insertions(+), 27 deletions(-) diff --git a/plugins/xslt-debugger/engine/impl/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/DebuggerServer.java b/plugins/xslt-debugger/engine/impl/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/DebuggerServer.java index 8952c4a65d7b..8993d2566fc4 100644 --- a/plugins/xslt-debugger/engine/impl/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/DebuggerServer.java +++ b/plugins/xslt-debugger/engine/impl/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/DebuggerServer.java @@ -43,10 +43,12 @@ public class DebuggerServer extends PortableRemoteObject implements RemoteDebugg private final RemoteBreakpointManagerImpl myBreakpointManager; private final RemoteEventQueueImpl myEventQueue; private final int myPort; + private final String myAccessToken; private DebuggerServer(Transformer transformer, Source xml, Result out, int port) throws TransformerConfigurationException, RemoteException { myPort = port; + myAccessToken = System.getProperty("xslt.debugger.token"); myDebugger = new LocalDebugger(transformer, xml, out) { @Override public void stop(boolean b) { @@ -115,15 +117,15 @@ public class DebuggerServer extends PortableRemoteObject implements RemoteDebugg } public Frame getCurrentFrame() throws RemoteException { - return RemoteFrameImpl.create(myDebugger.getCurrentFrame()); + return RemoteFrameImpl.create(myDebugger.getCurrentFrame(), myAccessToken); } public Frame getSourceFrame() throws RemoteException { - return RemoteFrameImpl.create(myDebugger.getSourceFrame()); + return RemoteFrameImpl.create(myDebugger.getSourceFrame(), myAccessToken); } - public Value eval(String expr) throws RemoteException, Debugger.EvaluationException { - return getCurrentFrame().eval(expr); + public Value eval(String expr, String accessToken) throws RemoteException, Debugger.EvaluationException { + return getCurrentFrame().eval(expr, accessToken); } public List getGlobalVariables() throws RemoteException { diff --git a/plugins/xslt-debugger/engine/lib/rmi-stubs.jar b/plugins/xslt-debugger/engine/lib/rmi-stubs.jar index 069ff156706a8898c27f2ccd67e5471a313b6640..0bdad2acb4fdd0a6e29b8f1bc5065aef1b4fa1df 100644 GIT binary patch delta 2242 zcmV;z2tD_<;Q_+k0kDlv6chje00;omnCwo53{%$a2LJ$t6qBJ(Q-7^jMX(b=5PbuL z4WD4a-GW1cySuwv2w{PRkicexySux)yE~jHiVFwePI2Nu6$J+6z_*+taV7d-DIYZ+9OeH|pVr8|&TJ=*A{Dwz{#+jqPsiaAT(%d)zqZ##J}2E7+@G zpMw1g4k$RN;E;mD3V)6$II7^7g5wHKC^)I$l!DU=&L}vm;Jkth3N9+Rln<5BLyDeK z^pc{t6n&)VD@8vk`sbhs2IRmiMQIGoK{*V{p<%GJ4v}JL4hmpc4oYIUT#d*ee`ML*Vu*8G0QUs+KCq+n# z@lu4Pm>@+0Q7K|l#64JzX&$V>JP+1Nu|Ym=hUUQ*%y+7FGKurj1wiU_*f-HcMZ1wh?S3 zP~4{Lud6e)SRx*5EKt~{A2P5O$khoBqnLmcwlxsVsuu=Cnil&^?+^!)F{53^g#& zoKkjQR|cfEGWQ=UP_5>l+uI}R6bZ%SL>G6$@%`EkdYh)p?65jr9+L?kkr8ay{2R%k zp-4i~X@BqFd(RIbgoj?Vf z*SMl-t=#uCv9X?OC39gmHr=zm12oJ~0}5jC`Fs^dHMnl6($nKb^M zdb_)_nKNi^77K?WsrIze(DR>)DBT=gW-`$sxvhQw9{=BVX1Dd2Ha)^SATgf4@(r33 zH72Wu7Upq>HctnGdF?R~o8OK$H=ZtrvIdI7V*3$`z>ew^|k`>QKq-jGx*b%q6qJ=KQJa z8#CQ?RwpLi>3WQSvUb3rM0m1EJ!P%vXn(bbQuz1gVW~T`juYNWft}6Z$$D&7vcOAa z>K8U=+B77p&YsRq)d_a9b2FvFE1j{|7`n4fmNv`i*DoxAZY*1Ws%-sM+4}8e>(>o` zvTXgyvh_QcZTD<7vp|D?{&FFaEPdsF(!`J!QQ5Y6jLBM@g}^db3DngImBN$N@KnxfDpP2H$|wi=Lw=OO z70ls!7Jyu6h8+1PAi#O7H3zMEoHd86dAv1;t$BhuyX9Yi5LgA6Pit&X`T1-h!snTQ zI0XgZ-0dprKS4gqQ}B3mZo@y~8h`40h3f$djL3Zz0U9Z#F<;Uc7&Ib}v;HO;T|*UT zhq-dop$Vw!49J}Z_?!WG(tv8t09P7N-5HQK4XEJ^P||>!&H#5BQ0o*54!Z~M2ygyd zsPpIw1R$D=Rw&AYoC}~W3Q?BeD2V|m1s$cajR$@mW$}sy@CoHbNmLNcQGbGORTQmJ zNwi00(UEgkxJ>0Oiq;wnnIm#(bj*6VjA# zG(#;k=Nm0h7cEU11L2mTrBcL|N>d|HP^Tz^$JS4+97Wv*6m zRTufWTENw8nGotrF+zcj(5ysUGqpf1D-l&iF|;w+_pb98B`)`_^GN7=azND z52;g@p-VZJPgAare3TtII>C$1v~?k-E0Nt;U)_o9!615?R2#!3H@B#IEn0&3BrSom z7A=7a78zlZ$s`Dur*N@%apF%J4%rl;!DD&Xs;+Gmv8t z;~Pxd5XLl=$YG3VIFTbz86$0M>ZaMaEjDG-Y$~MLRCZ*u6;m@DOf|A;mu6Gx{|{z7 zN0`A)piL!aB9W6A;$$K<1~?^42eU0BmFlF@DjQUEjyQueXn#u(Gn2?!3~V-$a~Rg# zEK%8>v0ZAAN~dhJ%TkVI3~o7XD~MT1?Cp*1KUmH9)`6yOH_7dJe69c(jgnCa+Kp3gF8;!31UtXd5VFZCh`o! zI-39302BZK00;omnCwo53{%$a2LJ$t6aWBC03-ka0000003ZMW z0EthN(IGpN;7=4P3IHGg000000RR{P6nC`7%Q)2mE8DZi%Q)2mE8DZi%Q)2mP)h*< z6a$m}SsDxg000000001_f#Fw^(IGpNP+Aw0AZ!eiux|vDGH@CKT3wUTAv=>$S`L$! Qa1{!p2mk;HW&i*H0Ki=&ZU6uP delta 2726 zcmV;X3R(5S-2t}Y0kDlv6bb+U2nYaIb@cum6V68<3Jj}rbQ;SC9Ymhcw| zf0ghz32#a`C*kiB{vqL?68&~JQW|nUEKH+J|cJX(I+|i6ess^@@Y;! zlZFY{%%zQ%cooT^m9Ip#(msmD<|7H`8oIn=(Y^u_5R4q?5tX8$^ zi3|g5ntyV2gI+y}VX#fMNK>1_u|&N3MurTVeCgtn>d6e(*+k0}Ev&4LsPXD43;~jjY3d6C&iq&h?8j7|tp-(3SeKZvb-B1m(R1qawXDa)M zD|Ia#ts`;35-0R^zGY4aLawI)h|;e56diHOiwT*$)ov9gc4qEXcp0lmap)Y(15^%ru! zSY0DlmuJ*O!qKoki@`g?9Jpu4YE_1Qvtx7^m8dRuiousmd7ObQpd;u|7g-le@vw^o z!;o6JF{;lUF0HbHVW5$K5Px?WO6GO=#nM7YRnatMV^G)x`IAB8NkUn} zBMnjqFb3TgM%hr#dMivEK?4U>tj&Pd4;mn7uY1XjxPnQH3}uD|9h0DSOoHYy3EGcI zP}76PF$o%nIp}nlDNVJpD6wIxrp2`E21Se4)4mgmY(=X}G^kOXwkpfeCZcw|rhn=Q zElM7E6K0Us#I$nZGF>!b>Rpr$RcWvU$*xRw(W4hrUC_KtjmMQbdOTH3j66wZYi8(A zBcmf)UejzXnl{B~%nW{eJErQinlP0CB`mwg$~oi6Ae=1EemtYv8l^@pR^s%4Hymw> zts_N7cllUbJgT=SyC+EQI@8I9f`8IlZ&YAZ^E*A-k8P zJf_c!C8D)`R_NK9tq6s*gtn)S*Gqc0tTZMLT(_V+Cj8G)*BJhJ<N7ePllD?P~ z8+!W1G#}PfqXCM5R6dN?aK|GUVJNZ@p?yA>k?8 z>}LGnExm?5tuDy@7GKF1s3g$2l*5GB16vVIxZ>|(M$)gvx6G^YBpj49G)Ah8+LP#g zQA@ppN{x@KT6Sr?YBQ)KQP(vmrJ2B>YQ^qSSw+U%NowSQ(EakV=w{zP0Y zSJ#)A?}oJXTG%=ubd#G(_e6#%2q24JV(8MAg`c2=9$X7<5QWY z+i{cggB}+>C=8}K8+eljMa~9N(qOu?ft)m$;cSqaG??jZ;7c0JayCdy8r<9rdAW=7 zbdYLdEqjNZ#|=~xjQ@MUs1ghy&WL+*J8{cFQAS+dYN`WN^eM!>xp|$KchD@l<7go% z*N=fq=mWWjuz#qv^eBQ=c^z2Xi4S%eZt0Uv{D|rK8SFQnWa(6%yg*O1VbuuTzQp)5I&4$UXvivUd_bBqK0$KT;nA1fWnSwc(kKtH_M#N2iHz8kzZP+fbKSH0e zg0~`1@OIoNcn3xi|1Qrm<=nxid385R**&Tl8QMTkHXXgAYmtl(P&+RfP7 z2N>eSPqlFT?vz{ZVU>42mk;fXaE2J0O4~wwEzGB diff --git a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebugger.java b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebugger.java index 255742575a01..a5319b93fc93 100644 --- a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebugger.java +++ b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebugger.java @@ -47,7 +47,7 @@ public interface RemoteDebugger extends Remote { Frame getSourceFrame() throws RemoteException; - Value eval(String expr) throws RemoteException, Debugger.EvaluationException; + Value eval(String expr, String accessToken) throws RemoteException, Debugger.EvaluationException; List getGlobalVariables() throws RemoteException; @@ -76,7 +76,7 @@ public interface RemoteDebugger extends Remote { String getXPath() throws RemoteException; - Value eval(String expr) throws RemoteException, Debugger.EvaluationException; + Value eval(String expr, String accessToken) throws RemoteException, Debugger.EvaluationException; List getVariables() throws RemoteException; diff --git a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebuggerClient.java b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebuggerClient.java index 8fe403028253..276adf7490e6 100644 --- a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebuggerClient.java +++ b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteDebuggerClient.java @@ -30,11 +30,13 @@ import java.util.List; public class RemoteDebuggerClient implements Debugger { private final RemoteDebugger myRemote; + private final String myAccessToken; private final BreakpointManager myBreakpointManager; private final OutputEventQueue myEventQueue; - public RemoteDebuggerClient(int port) throws IOException, NotBoundException { + public RemoteDebuggerClient(int port, String accessToken) throws IOException, NotBoundException { myRemote = (RemoteDebugger)Naming.lookup("rmi://127.0.0.1:" + port + "/XsltDebugger"); + myAccessToken = accessToken; final RemoteBreakpointManager manager = myRemote.getBreakpointManager(); myBreakpointManager = new MyBreakpointManager(manager); @@ -144,7 +146,7 @@ public class RemoteDebuggerClient implements Debugger { public StyleFrame getCurrentFrame() { try { - return MyFrame.create(myRemote.getCurrentFrame()); + return new MyFrame(myRemote.getCurrentFrame()); } catch (RemoteException e) { throw handleRemoteException(e); } @@ -152,7 +154,7 @@ public class RemoteDebuggerClient implements Debugger { public SourceFrame getSourceFrame() { try { - return MySourceFrame.create(myRemote.getSourceFrame()); + return new MySourceFrame(myRemote.getSourceFrame()); } catch (RemoteException e) { throw handleRemoteException(e); } @@ -160,7 +162,7 @@ public class RemoteDebuggerClient implements Debugger { public Value eval(String expr) throws EvaluationException { try { - return myRemote.eval(expr); + return myRemote.eval(expr, myAccessToken); } catch (RemoteException e) { throw handleRemoteException(e); } @@ -348,7 +350,7 @@ public class RemoteDebuggerClient implements Debugger { } } - private static abstract class MyAbstractFrame implements Frame { + private abstract class MyAbstractFrame implements Frame { protected final RemoteDebugger.Frame myFrame; protected MyAbstractFrame(RemoteDebugger.Frame frame) { @@ -399,7 +401,7 @@ public class RemoteDebuggerClient implements Debugger { public Value eval(String expr) throws EvaluationException { try { - return myFrame.eval(expr); + return myFrame.eval(expr, myAccessToken); } catch (RemoteException e) { throw handleRemoteException(e); } @@ -414,7 +416,7 @@ public class RemoteDebuggerClient implements Debugger { } } - private static class MyFrame extends MyAbstractFrame implements StyleFrame { + private class MyFrame extends MyAbstractFrame implements StyleFrame { protected MyFrame(RemoteDebugger.Frame frame) { super(frame); } @@ -432,12 +434,12 @@ public class RemoteDebuggerClient implements Debugger { return create(frame); } - public static StyleFrame create(RemoteDebugger.Frame currentFrame) { + public StyleFrame create(RemoteDebugger.Frame currentFrame) { return currentFrame != null ? new MyFrame(currentFrame) : null; } } - private static class MySourceFrame extends MyAbstractFrame implements SourceFrame { + private class MySourceFrame extends MyAbstractFrame implements SourceFrame { protected MySourceFrame(RemoteDebugger.Frame frame) { super(frame); } @@ -447,7 +449,7 @@ public class RemoteDebuggerClient implements Debugger { return create(frame); } - public static SourceFrame create(RemoteDebugger.Frame currentFrame) { + public SourceFrame create(RemoteDebugger.Frame currentFrame) { return currentFrame != null ? new MySourceFrame(currentFrame) : null; } } diff --git a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteFrameImpl.java b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteFrameImpl.java index f5501e54c643..75c5817c3573 100644 --- a/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteFrameImpl.java +++ b/plugins/xslt-debugger/engine/src/org/intellij/plugins/xsltDebugger/rt/engine/remote/RemoteFrameImpl.java @@ -26,9 +26,11 @@ import java.util.List; class RemoteFrameImpl extends PortableRemoteObject implements RemoteDebugger.Frame { private final Frame myFrame; + private final String myAccessToken; - private RemoteFrameImpl(Frame frame) throws RemoteException { + private RemoteFrameImpl(Frame frame, String accessToken) throws RemoteException { myFrame = frame; + myAccessToken = accessToken; } public int getLineNumber() { @@ -40,18 +42,19 @@ class RemoteFrameImpl extends PortableRemoteObject implements RemoteDebugger.Fra } public RemoteDebugger.Frame getNext() throws RemoteException { - return create(myFrame.getNext()); + return create(myFrame.getNext(), myAccessToken); } public RemoteDebugger.Frame getPrevious() throws RemoteException { - return create(myFrame.getPrevious()); + return create(myFrame.getPrevious(), myAccessToken); } public String getXPath() throws RemoteException { return ((Debugger.SourceFrame)myFrame).getXPath(); } - public ValueImpl eval(String expr) throws Debugger.EvaluationException { + public ValueImpl eval(String expr, String accessToken) throws Debugger.EvaluationException, RemoteException { + if (!myAccessToken.equals(accessToken)) throw new RemoteException("Access denied"); final Value value = ((Debugger.StyleFrame)myFrame).eval(expr); return new ValueImpl(value.getValue(), value.getType()); } @@ -64,7 +67,7 @@ class RemoteFrameImpl extends PortableRemoteObject implements RemoteDebugger.Fra return ((Debugger.StyleFrame)myFrame).getInstruction(); } - public static RemoteFrameImpl create(Frame frame) throws RemoteException { - return frame != null ? new RemoteFrameImpl(frame) : null; + public static RemoteFrameImpl create(Frame frame, String accessToken) throws RemoteException { + return frame != null ? new RemoteFrameImpl(frame, accessToken) : null; } } diff --git a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebugProcessListener.java b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebugProcessListener.java index 58920fa86ef2..38efd2585446 100644 --- a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebugProcessListener.java +++ b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebugProcessListener.java @@ -29,15 +29,17 @@ import org.jetbrains.annotations.NotNull; class DebugProcessListener extends ProcessAdapter { private final Project myProject; private final int myPort; + private final String myAccessToken; - DebugProcessListener(Project project, int port) { + DebugProcessListener(Project project, int port, String accessToken) { myProject = project; myPort = port; + myAccessToken = accessToken; } @Override public void startNotified(@NotNull ProcessEvent event) { - final DebuggerConnector connector = new DebuggerConnector(myProject, event.getProcessHandler(), myPort); + final DebuggerConnector connector = new DebuggerConnector(myProject, event.getProcessHandler(), myPort, myAccessToken); ApplicationManager.getApplication().executeOnPooledThread(connector); } diff --git a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebuggerConnector.java b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebuggerConnector.java index 2065dbf261ac..cb5ae2f74f49 100644 --- a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebuggerConnector.java +++ b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/DebuggerConnector.java @@ -40,11 +40,13 @@ class DebuggerConnector implements Runnable { private final Project myProject; private final ProcessHandler myProcess; private final int myPort; + private final String myAccessToken; - DebuggerConnector(Project project, ProcessHandler process, int port) { + DebuggerConnector(Project project, ProcessHandler process, int port, String accessToken) { myProject = project; myProcess = process; myPort = port; + myAccessToken = accessToken; } @Override @@ -97,7 +99,7 @@ class DebuggerConnector implements Runnable { if (myProcess.isProcessTerminated()) return null; try { - final Debugger realClient = EDTGuard.create(new RemoteDebuggerClient(myPort), myProcess); + final Debugger realClient = EDTGuard.create(new RemoteDebuggerClient(myPort, myAccessToken), myProcess); myProcess.notifyTextAvailable("Connected to XSLT debugger on port " + myPort + "\n", ProcessOutputTypes.SYSTEM); return realClient; } catch (ConnectException e) { diff --git a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/XsltDebuggerExtension.java b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/XsltDebuggerExtension.java index b6b6a7fa0db8..68ecbd360765 100644 --- a/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/XsltDebuggerExtension.java +++ b/plugins/xslt-debugger/src/org/intellij/plugins/xsltDebugger/XsltDebuggerExtension.java @@ -57,6 +57,7 @@ import org.jetbrains.annotations.Nullable; import java.io.File; import java.io.IOException; import java.util.List; +import java.util.UUID; import java.util.jar.Attributes; import java.util.jar.Manifest; @@ -70,6 +71,7 @@ public class XsltDebuggerExtension extends XsltRunnerExtension { public static final Key VERSION = Key.create("VERSION"); private static final Key PORT = Key.create("PORT"); private static final Key MANIFEST = Key.create("MANIFEST"); + private static final Key ACCESS_TOKEN = Key.create("access token"); @NonNls private static final String SAXON_6_JAR = "saxon.jar"; @@ -87,7 +89,7 @@ public class XsltDebuggerExtension extends XsltRunnerExtension { public ProcessListener createProcessListener(Project project, UserDataHolder extensionData) { final Integer port = extensionData.getUserData(PORT); assert port != null; - return new DebugProcessListener(project, port); + return new DebugProcessListener(project, port, extensionData.getUserData(ACCESS_TOKEN)); } @Override @@ -130,6 +132,10 @@ public class XsltDebuggerExtension extends XsltRunnerExtension { throw new CantRunException("Unable to find a free network port"); } + String token = UUID.randomUUID().toString(); + parameters.getVMParametersList().defineProperty("xslt.debugger.token", token); + extensionData.putUserData(ACCESS_TOKEN, token); + final char c = File.separatorChar; final PluginId pluginId = PluginManagerCore.getPluginByClassName(getClass().getName());