You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Java代码中Stored Absolute Path Traversal告警排查求助

解决Checkmarx「Stored Absolute Path Traversal」告警问题

我的Java代码里,下面两个文件读取操作触发了Checkmarx的「Stored Absolute Path Traversal」告警:

byte[] buffer = Files.readAllBytes(dir);
Files.readAllLines(dir)

dir的初始创建逻辑是这样的:

Path dir = Paths.get(Paths.get(base, parts).normalize().toString().replace(" ", "_"));

试过路径规范化、替换空格,甚至用File.getCanonicalPath()处理:

String canonicalPath;
String path = Paths.get(base, parts)
    .normalize()
    .toString().replace(" ", "_");
try {
    canonicalPath = new File(path).getCanonicalPath();
} catch (Exception e) {
    throw new RuntimeException(e);
}

但告警还是没消,求可行的解决办法。


问题根源

Checkmarx这类静态扫描工具不会只看路径是否规范化,核心是要确认路径严格限制在你预期的安全目录范围内。单纯的转义或规范化,没法向工具证明路径没有越权访问敏感目录的风险。

可行的解决思路

1. 强制路径落在指定根目录内

先明确允许访问的根目录,然后校验最终路径是不是这个根目录的子路径,直接拒绝越权路径。示例代码:

// 定义允许访问的安全根目录,比如应用专属的资源目录
Path allowedRoot = Paths.get("/opt/app/secure_files").toAbsolutePath().normalize();

// 处理原始路径:规范化、转义空格、转为绝对路径
Path rawPath = Paths.get(base, parts).normalize();
Path absolutePath = rawPath.isAbsolute() ? rawPath : allowedRoot.resolve(rawPath);
String processedPathStr = absolutePath.toString().replace(" ", "_");
Path processedPath = Paths.get(processedPathStr).toAbsolutePath().normalize();

// 关键校验:确保路径在安全根目录下
if (!processedPath.startsWith(allowedRoot)) {
    throw new SecurityException("非法路径访问,拒绝操作");
}

// 后续安全执行文件操作
byte[] buffer = Files.readAllBytes(processedPath);

2. 基于根目录直接构建路径(推荐)

如果parts是相对路径片段,直接从安全根目录出发构建路径,从源头避免绝对路径注入风险:

Path allowedRoot = Paths.get("/opt/app/secure_files").toAbsolutePath().normalize();

// 直接从根目录解析相对路径,自动处理../这类跳转
Path safePath = allowedRoot.resolve(parts).normalize().toAbsolutePath();

// 二次校验防止异常情况(比如parts包含绝对路径前缀)
if (!safePath.startsWith(allowedRoot)) {
    throw new SecurityException("非法路径访问,拒绝操作");
}

// 替换空格后执行操作
Path finalPath = Paths.get(safePath.toString().replace(" ", "_"));
Files.readAllLines(finalPath);

3. 统一使用Java NIO Path API

之前混用Paths和File可能导致路径处理逻辑不一致,容易被扫描工具误判。全程用NIO的Path API处理路径,逻辑更统一:

Path allowedRoot = Paths.get("/opt/app/secure_files").toAbsolutePath().normalize();

Path processedPath = Paths.get(base, parts)
    .normalize()
    .toAbsolutePath()
    .toString()
    .replace(" ", "_");
processedPath = Paths.get(processedPath).toAbsolutePath().normalize();

if (!processedPath.startsWith(allowedRoot)) {
    throw new SecurityException("非法路径访问,拒绝操作");
}

byte[] buffer = Files.readAllBytes(processedPath);

核心注意点

  • 必须明确安全根目录,这是扫描工具认可的关键约束
  • 校验逻辑一定要放在文件读写操作之前,提前拦截非法路径
  • 避免使用用户输入直接构建绝对路径,尽量基于安全根目录解析相对路径

内容的提问来源于stack exchange,提问作者Jelly

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.10 23:05:02