You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何修复Spring项目中SonarQube检测到的CWE-259/CWE-321漏洞

修复Spring项目中SonarQube检测到的CWE-259/CWE-321硬编码密钥漏洞

我在使用SonarQube扫描Spring框架项目时,检测到多个CWE-259和CWE-321漏洞,这类漏洞都和硬编码密码或密钥相关。我尝试过将密钥存储到数据库、本地文件等方式,但都没能解决问题,以下是我尝试的示例代码:

public static String generateHMAC(Map data) throws Exception {
    try {
        
        ObjectMapper objectMapper = new ObjectMapper();
        String jsonData = objectMapper.writeValueAsString(data);
        EncryptPropertyService encryptPropertyService = (EncryptPropertyService)MyApplicationContext.getCtx().getBean("encryptPropertyService");

        String encryptedKey = getPassword("/app/project/keys/password.ini");
        String key = encryptPropertyService.generatePropertyDecStringValue(encryptedKey);
          
        
        //The below line is the problem
        SecretKeySpec secretKeySpec = new SecretKeySpec(key.getBytes(StandardCharsets.UTF_8), "HmacSHA256");

        Mac mac = Mac.getInstance("HmacSHA256");
        mac.init(secretKeySpec);
        byte[] hmacBytes = mac.doFinal(jsonData.getBytes());
        return Base64.getEncoder().encodeToString(hmacBytes);
    } catch (Exception e) {
        logger.error("[HMACUtil.generateHMAC] error : "+e);
        throw new Exception(e);
    }
}

恳请各位提供有效的修复方案。

内容的提问来源于stack exchange,提问作者taehee lim

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.13 10:23:24