Find injection vectors
Recipe ID
org.openrewrite.kotlin.security.FindInjectionVectors$KtRecipeArtifact
io.moderne.recipe:recipes-kotlinSQL string concatenation into Statement/PreparedStatement, command injection via Runtime.exec and ProcessBuilder, path traversal via File concatenation, unsafe reflection via Class.forName(input), and dynamic-script evaluation via ScriptEngine.
Usage
This recipe has no required configuration options. You’ll need the Moderne CLI configured before running the command below.
mod run . --recipe org.openrewrite.kotlin.security.FindInjectionVectors$KtRecipeIf the recipe isn’t available locally, install it with:
mod config recipes jar install io.moderne.recipe:recipes-kotlin:0.2.0Definition
This recipe runs the following recipes in order.
- Find
Statement.executeQuery("... " + x)callsorg.openrewrite.kotlin.security.FindSqlExecuteQueryWithConcat$KtRecipe - Find
Statement.execute("... " + x)/executeUpdatecallsorg.openrewrite.kotlin.security.FindSqlExecuteWithConcat$KtRecipe - Find
prepareStatement("... " + x)callsorg.openrewrite.kotlin.security.FindPrepareStatementWithConcat$KtRecipe - Find
Runtime.getRuntime().exec(...)calls with non-literal argumentsorg.openrewrite.kotlin.security.FindRuntimeExecWithNonLiteral$KtRecipe - Find
ProcessBuilder(varargs)constructions whose first arg is non-literalorg.openrewrite.kotlin.security.FindProcessBuilderWithNonLiteral$KtRecipe - Find
File("..." + input)constructionsorg.openrewrite.kotlin.security.FindFilePathConcat$KtRecipe - Find
Class.forName(...)calls with non-literal argumentsorg.openrewrite.kotlin.security.FindClassForNameWithNonLiteral$KtRecipe - Find
ScriptEngine.eval(...)callsorg.openrewrite.kotlin.security.FindScriptEngineEval$KtRecipe - Find
ScriptEngineManager.getEngineByName(...)callsorg.openrewrite.kotlin.security.FindScriptEngineManager$KtRecipe - Find
InitialContext.lookup(input)calls with non-literal argumentsorg.openrewrite.kotlin.security.FindJndiLookupWithNonLiteral$KtRecipe - Find
Paths.get("..." + input)callsorg.openrewrite.kotlin.security.FindPathsGetWithConcat$KtRecipe - Find
HttpServletResponse.sendRedirect(input)calls with non-literal argumentsorg.openrewrite.kotlin.security.FindResponseSendRedirectWithNonLiteral$KtRecipe
Data tables
Structured output this recipe can produce.
- Source files that had resultsSource files that were modified by the recipe run.
org.openrewrite.table.SourcesFileResults - Source files that had search resultsSearch results that were found during the recipe run.
org.openrewrite.table.SearchResults - Source files that errored on a recipeThe details of all errors produced by a recipe run.
org.openrewrite.table.SourcesFileErrors - Recipe performanceStatistics used in analyzing the performance of recipes.
org.openrewrite.table.RecipeRunStats