如何修复Spring项目中SonarQube检测到的CWE-259/CWE-321漏洞
修复Spring项目中SonarQube检测到的CWE-259/CWE-321硬编码密钥漏洞
我在使用SonarQube扫描Spring框架项目时,检测到多个CWE-259和CWE-321漏洞,这类漏洞都和硬编码密码或密钥相关。我尝试过将密钥存储到数据库、本地文件等方式,但都没能解决问题,以下是我尝试的示例代码:
public static String generateHMAC(Map data) throws Exception { try { ObjectMapper objectMapper = new ObjectMapper(); String jsonData = objectMapper.writeValueAsString(data); EncryptPropertyService encryptPropertyService = (EncryptPropertyService)MyApplicationContext.getCtx().getBean("encryptPropertyService"); String encryptedKey = getPassword("/app/project/keys/password.ini"); String key = encryptPropertyService.generatePropertyDecStringValue(encryptedKey); //The below line is the problem SecretKeySpec secretKeySpec = new SecretKeySpec(key.getBytes(StandardCharsets.UTF_8), "HmacSHA256"); Mac mac = Mac.getInstance("HmacSHA256"); mac.init(secretKeySpec); byte[] hmacBytes = mac.doFinal(jsonData.getBytes()); return Base64.getEncoder().encodeToString(hmacBytes); } catch (Exception e) { logger.error("[HMACUtil.generateHMAC] error : "+e); throw new Exception(e); } }
恳请各位提供有效的修复方案。
内容的提问来源于stack exchange,提问作者taehee lim
相关产品推荐
相关产品推荐

