如何修复Veracode扫描出的HTTP头CRLF序列未正确中和(CWE-113)漏洞
Got it, let's break down how to fix this Veracode-flagged issue in your writeCookies() method. The problem here is that if any part of the Cookie object (name, value, domain, path, etc.) contains CRLF characters (\r\n), an attacker could exploit this to split the HTTP response and inject malicious headers or content—exactly what CWE-113 warns about.
Here's how to address it step by step:
1. Sanitize All Cookie Fields to Remove CRLF Characters
The core fix is to strip out any \r or \n characters from every part of the cookie before passing it to super.addCookie(). Create a helper method to sanitize the cookie:
private Cookie sanitizeCookie(Cookie inputCookie) { // Clean cookie name by removing CRLF and invalid characters String safeName = inputCookie.getName().replaceAll("[\\r\\n]", ""); // Clean cookie value the same way String safeValue = inputCookie.getValue().replaceAll("[\\r\\n]", ""); // Create a new sanitized cookie instance Cookie sanitizedCookie = new Cookie(safeName, safeValue); // Sanitize other user-controlled cookie properties (if applicable) if (inputCookie.getDomain() != null) { sanitizedCookie.setDomain(inputCookie.getDomain().replaceAll("[\\r\\n]", "")); } if (inputCookie.getPath() != null) { sanitizedCookie.setPath(inputCookie.getPath().replaceAll("[\\r\\n]", "")); } // Copy over non-sensitive, safe properties from the original cookie sanitizedCookie.setMaxAge(inputCookie.getMaxAge()); sanitizedCookie.setSecure(inputCookie.getSecure()); sanitizedCookie.setHttpOnly(inputCookie.isHttpOnly()); sanitizedCookie.setVersion(inputCookie.getVersion()); return sanitizedCookie; }
Then update your writeCookies() method to use this sanitized cookie instead of the original:
public void writeCookies() { for (final Cookie cookie : cookies) { Cookie safeCookie = sanitizeCookie(cookie); super.addCookie(safeCookie); } }
2. Add Strict Validation for User-Controlled Cookie Data
Sanitization is great, but it's even better to block invalid input at the source. If the cookie data comes from user input (like form fields, URL parameters, etc.), validate it against a strict pattern to ensure it doesn't contain forbidden characters:
private boolean isCookieNameValid(String name) { // Follow RFC 6265 standards for valid cookie names return name != null && name.matches("[\\w!#$%&'*+-.^_`|~]+"); } private boolean isCookieValueValid(String value) { // Allow only safe characters for cookie values return value != null && value.matches("[\\w!#$%&'()*+,-./:<=>?@\\[\\]^_`{|}~]*"); }
You can add checks in your sanitize method (or before creating the cookie) to reject invalid values entirely:
private Cookie sanitizeCookie(Cookie inputCookie) { if (!isCookieNameValid(inputCookie.getName()) || !isCookieValueValid(inputCookie.getValue())) { // Handle invalid cookie—throw an exception, log a warning, or skip adding it throw new IllegalArgumentException("Invalid cookie data detected"); } // Rest of the sanitization logic... }
3. Don't Rely Solely on Container-Level Protection
While some modern servlet containers have built-in safeguards against response splitting, you shouldn't depend on them alone. Veracode is flagging this because it can't confirm the container will handle it, so adding your own sanitization/validation is the safest approach.
By implementing these steps, you'll neutralize the CRLF sequence risk that's triggering the CWE-113 alert. The key is ensuring no untrusted input can introduce line breaks into the HTTP response headers via cookies.
内容的提问来源于stack exchange,提问作者Nicolas

