diff --git a/java/jenkins/credentials/lookup-null-authentication.yaml b/java/jenkins/credentials/lookup-null-authentication.yaml new file mode 100644 index 0000000..f813870 --- /dev/null +++ b/java/jenkins/credentials/lookup-null-authentication.yaml @@ -0,0 +1,29 @@ +rules: + - id: codevigilant.java.jenkins.credentials.lookup-null-authentication + patterns: + - pattern-either: + - pattern: CredentialsProvider.lookupCredentials($TYPE, $CTX, null) + - pattern: CredentialsProvider.lookupCredentials($TYPE, $CTX, null, $EXTRA) + - pattern: com.cloudbees.plugins.credentials.CredentialsProvider.lookupCredentials($TYPE, $CTX, null) + - pattern: com.cloudbees.plugins.credentials.CredentialsProvider.lookupCredentials($TYPE, $CTX, null, $EXTRA) + message: | + Detected CredentialsProvider.lookupCredentials invoked with a null + authentication argument. In the Credentials plugin, a null Authentication + is treated as ACL.SYSTEM, so the lookup returns credentials the current + user and current item may not be allowed to use. Resolve credentials with + the caller's authentication and the owning Item/ItemGroup, e.g. + CredentialsProvider.findCredentialById(id, type, item). + metadata: + category: security + cwe: "CWE-522: Insufficiently Protected Credentials" + owasp: "A01:2021 - Broken Access Control" + technology: jenkins + confidence: HIGH + references: + - https://www.jenkins.io/doc/developer/security/ + - https://javadoc.jenkins.io/plugin/credentials/com/cloudbees/plugins/credentials/CredentialsProvider.html + source: independent security review + license: MIT + languages: [java] + mode: search + severity: HIGH