CWE-104 Variante Rascunho

Struts: Form Bean Does Not Extend Validation Class

This vulnerability occurs in Apache Struts applications when a form bean class does not properly extend the framework's validation class. This bypasses the built-in Validator framework, leaving the…

Definição

What is CWE-104?

This vulnerability occurs in Apache Struts applications when a form bean class does not properly extend the framework's validation class. This bypasses the built-in Validator framework, leaving the application without structured input validation and open to various injection and data manipulation attacks.
In Struts, the Validator framework provides a centralized, declarative way to validate user input across forms. When a developer creates a form bean that doesn't extend `ActionForm` (or its Validator subclass), the application misses out on this essential security layer. Instead, input checks become ad-hoc, inconsistent, or entirely absent, making every data field a potential entry point for malicious data. To prevent this, always ensure your form beans inherit from the appropriate validation-enabled class, such as `ValidatorForm`. This enforces validation rules defined in your `validation.xml` configuration file, ensuring all user input is cleaned and checked before processing. Consistently using the framework's validation mechanism is far more reliable and secure than attempting to manually validate each input throughout your codebase.
Impacto no mundo real

Real-world CVEs caused by CWE-104

Ainda não há referências CVE públicas associadas a este CWE no catálogo da MITRE.

Como os atacantes a exploram

Trajeto do atacante passo a passo

  1. 1

    In the following Java example the class RegistrationForm is a Struts framework ActionForm Bean that will maintain user information from a registration webpage for an online business site. The user will enter registration data and through the Struts framework the RegistrationForm bean will maintain the user data.

  2. 2

    However, the RegistrationForm class extends the Struts ActionForm class which does not allow the RegistrationForm class to use the Struts validator capabilities. When using the Struts framework to maintain user data in an ActionForm Bean, the class should always extend one of the validator classes, ValidatorForm, ValidatorActionForm, DynaValidatorForm or DynaValidatorActionForm. These validator classes provide default validation and the validate method for custom validation for the Bean object to use for validating input data. The following Java example shows the RegistrationForm class extending the ValidatorForm class and implementing the validate method for validating input data.

  3. 3

    Note that the ValidatorForm class itself extends the ActionForm class within the Struts framework API.

Exemplo de código vulnerável

Vulnerable Java

In the following Java example the class RegistrationForm is a Struts framework ActionForm Bean that will maintain user information from a registration webpage for an online business site. The user will enter registration data and through the Struts framework the RegistrationForm bean will maintain the user data.

Vulnerável Java
public class RegistrationForm extends org.apache.struts.action.ActionForm {
  		// private variables for registration form
  		private String name;
  		private String email;
  		...
  		public RegistrationForm() {
  			super();
  		}
  		// getter and setter methods for private variables
  		...
  }
Exemplo de código seguro

Secure Java

However, the RegistrationForm class extends the Struts ActionForm class which does not allow the RegistrationForm class to use the Struts validator capabilities. When using the Struts framework to maintain user data in an ActionForm Bean, the class should always extend one of the validator classes, ValidatorForm, ValidatorActionForm, DynaValidatorForm or DynaValidatorActionForm. These validator classes provide default validation and the validate method for custom validation for the Bean object to use for validating input data. The following Java example shows the RegistrationForm class extending the ValidatorForm class and implementing the validate method for validating input data.

Seguro Java
public class RegistrationForm extends org.apache.struts.validator.ValidatorForm {
  		// private variables for registration form
  		private String name;
  		private String email;
  		...
  		public RegistrationForm() {
  			super();
  		}
  		public ActionErrors validate(ActionMapping mapping, HttpServletRequest request) {...}
  		// getter and setter methods for private variables
  		...
  }
What changed: the unsafe sink is replaced (or the input is validated/escaped) so the same payload no longer triggers the weakness.
Lista de verificação de prevenção

How to prevent CWE-104

  • Implementation Ensure that all forms extend one of the Validation Classes.
Sinais de deteção

How to detect CWE-104

Automated Static Analysis High

Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)

Correção automática do Plexicus

O Plexicus deteta automaticamente o CWE-104 e abre um PR de correção em menos de 60 segundos.

O Codex Remedium analisa cada commit, identifica esta fraqueza exata e entrega um pull request pronto para revisão com o patch. Sem tickets. Sem transferências.

Perguntas frequentes

Frequently asked questions

O que é o CWE-104?

This vulnerability occurs in Apache Struts applications when a form bean class does not properly extend the framework's validation class. This bypasses the built-in Validator framework, leaving the application without structured input validation and open to various injection and data manipulation attacks.

Qual a gravidade do CWE-104?

A MITRE não publicou uma classificação de probabilidade de exploração para esta fraqueza. Trate-a como impacto médio até o seu modelo de ameaças provar o contrário.

Que linguagens ou plataformas são afetadas pelo CWE-104?

MITRE lists the following affected platforms: Java.

Como posso prevenir o CWE-104?

Ensure that all forms extend one of the Validation Classes.

Como é que o Plexicus deteta e corrige o CWE-104?

O motor SAST do Plexicus correlaciona a assinatura de fluxo de dados do CWE-104 em cada commit. Quando é encontrada uma correspondência, o nosso agente Codex Remedium abre um PR de correção com o código corrigido, testes e um resumo de uma linha para o revisor.

Onde posso saber mais sobre o CWE-104?

A MITRE publica a definição canónica em https://cwe.mitre.org/data/definitions/104.html. Pode também consultar a documentação da OWASP e do NIST para orientações adjacentes.

Fraquezas relacionadas

Weaknesses related to CWE-104

CWE-573 Pai

Improper Following of Specification by Caller

This weakness occurs when software fails to properly follow the documented rules, protocols, or requirements of an external component it…

CWE-103 Irmão

Struts: Incomplete validate() Method Definition

This vulnerability occurs in a Struts application when a validator form either completely omits a validate() method or includes one but…

CWE-243 Irmão

Creation of chroot Jail Without Changing Working Directory

This vulnerability occurs when a program creates a chroot jail but fails to change its current working directory afterward. Because the…

CWE-253 Irmão

Incorrect Check of Function Return Value

This vulnerability occurs when a program misinterprets or improperly validates the return value from a function, causing it to miss…

CWE-296 Irmão

Improper Following of a Certificate's Chain of Trust

This vulnerability occurs when software fails to properly validate the entire certificate chain back to a trusted root authority. This…

CWE-304 Irmão

Missing Critical Step in Authentication

This vulnerability occurs when a software authentication process omits a required step, weakening its overall security.

CWE-325 Irmão

Missing Cryptographic Step

This vulnerability occurs when a software implementation skips a critical step in a cryptographic process, resulting in security that is…

CWE-329 Irmão

Generation of Predictable IV with CBC Mode

This vulnerability occurs when software uses a predictable or reused Initialization Vector (IV) with Cipher Block Chaining (CBC) mode…

CWE-358 Irmão

Improperly Implemented Security Check for Standard

This vulnerability occurs when software fails to correctly implement one or more critical security checks required by a standard protocol,…

Pronto quando você estiver

Pare de pagar por desenvolvedor.
Comece a fechar o ciclo.

O Plexicus é o ASPM nativo de IA que verifica, filtra, corrige, pentesta e explica — de forma autónoma. Programadores ilimitados, repos ilimitados, ações de IA de utilização justa. Nível gratuito real, €269/mo anual quando estiver pronto.