Harden XML parsing, serialization, and randomness (#3075)

This commit introduces several security hardening improvements across the codebase:
1. XML Processing: Hardened `TransformerFactory` and `SchemaFactory` instantiations in `EppMessage.java` by explicitly enabling `XMLConstants.FEATURE_SECURE_PROCESSING` and disabling external schema access.
2. Randomness: Replaced instances of `java.util.Random` with `java.security.SecureRandom` in `SelfSignedCaCertificate.java` for stronger entropy. (Added documentation in `ProxyModule.java` explaining why `java.util.Random` is intentionally retained there for metrics sampling).
3. Deserialization: Hardened `SerializeUtils.java` by injecting an `ObjectInputFilter` into the `ObjectInputStream`, restricting deserialization strictly to expected `google.registry` classes and standard Java collections.
This commit is contained in:
Ben McIlwain
2026-06-01 14:25:42 +00:00
committed by GitHub
parent c5abd2a7c9
commit 0030645b1a
7 changed files with 60 additions and 5 deletions
@@ -177,6 +177,8 @@ public class EppMessage {
new StreamSource(readResource(path + "launch.xsd")),
};
SchemaFactory schemaFactory = SchemaFactory.newInstance(XMLConstants.W3C_XML_SCHEMA_NS_URI);
schemaFactory.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
schemaFactory.setProperty(XMLConstants.ACCESS_EXTERNAL_SCHEMA, "");
eppSchema = schemaFactory.newSchema(sources);
} catch (SAXException | IOException e) {
throw new ExceptionInInitializerError(e);
@@ -271,7 +273,9 @@ public class EppMessage {
return null;
}
try {
Transformer transformer = TransformerFactory.newInstance().newTransformer();
TransformerFactory tf = TransformerFactory.newInstance();
tf.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
Transformer transformer = tf.newTransformer();
StreamResult result = new StreamResult(new StringWriter());
DOMSource source = new DOMSource(xml);
transformer.transform(source, result);
@@ -291,7 +295,9 @@ public class EppMessage {
*/
public static byte[] xmlDocToByteArray(Document xml) throws EppClientException {
try {
Transformer transformer = TransformerFactory.newInstance().newTransformer();
TransformerFactory tf = TransformerFactory.newInstance();
tf.setFeature(XMLConstants.FEATURE_SECURE_PROCESSING, true);
Transformer transformer = tf.newTransformer();
StreamResult result = new StreamResult(new StringWriter());
DOMSource source = new DOMSource(xml);
transformer.transform(source, result);