You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Spring Boot中解决Checkmarx Codegate敏感信息非安全传输问题

解决Checkmarx Codegate阻断问题的方案

核心原因

Checkmarx触发告警的本质不是fromAddress的存储方式(迁移到Azure KeyVault已满足存储安全要求),而是它检测到该字段通过未加密的网络通道传输。以下是具体解决方法:

1. 强制SMTP传输使用SSL/TLS加密

确保JavaMail的Session配置启用加密传输,彻底消除明文传输风险,直接阻断Checkmarx的检测触发点:

Properties props = new Properties();
// 启用SMTP SSL加密
props.put("mail.smtp.ssl.enable", "true");
// 强制要求SSL连接,拒绝非加密请求
props.put("mail.smtp.ssl.required", "true");
// 若服务使用STARTTLS协议,补充以下配置
props.put("mail.smtp.starttls.enable", "true");
props.put("mail.smtp.starttls.required", "true");

Session session = Session.getInstance(props, authenticator);

2. 标记字段为非敏感PII

如果fromAddress是企业公共邮箱而非个人隐私邮箱,可通过两种方式消除误报:

  • 在代码中添加Checkmarx专用注释,跳过该字段的敏感数据检测:
    // CHECKMARX: OFF - fromAddress为企业共享邮箱,不属于个人敏感信息
    @Value("${forsee.emailservice.email}")
    public String fromAddress;
    // CHECKMARX: ON
    
  • 向团队的Checkmarx管理员提交误报申诉,说明该字段属于企业公共资源,不属于PII(个人可识别信息)范畴。

3. 启用邮件端到端加密(进阶方案)

若需要更高安全等级,可使用S/MIME对MimeMessage进行加密,确保邮件内容即使在传输链路中被拦截也无法解密:

// 加载发送方加密证书(替换为实际证书路径与密码)
InputStream certStream = new FileInputStream("sender_cert.p12");
KeyStore ks = KeyStore.getInstance("PKCS12");
ks.load(certStream, "cert_password".toCharArray());
X509Certificate cert = (X509Certificate) ks.getCertificate("cert_alias");

// 加密邮件内容
SMIMEEncrypter encrypter = new SMIMEEncrypter();
encrypter.addRecipientCertificate(cert);
MimeMessage encryptedMessage = encrypter.encrypt(message);

4. 调整Checkmarx扫描规则(管理员操作)

如果团队内多个服务都存在类似企业邮箱的误报,可由Checkmarx管理员修改扫描规则:

  • 排除特定包路径(如com.samsclub.forsee.services)下的fromAddress字段检测
  • 更新敏感数据识别规则,将企业邮箱格式从PII检测范围中排除

内容的提问来源于stack exchange,提问作者PAMPA ROY

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.18 00:55:00