The analyzer has detected that potentially sensitive data is being processed using values from an insecure random number generator.
This vulnerability type falls under the following OWASP Top 10 categories:
The example:
Random random = new Random();
long token = random.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token)); // <=
This example shows how a token is generated that can be used to save and restore a user's session. It is created using a standard pseudorandom number generator, which operates in a predictable way. If a server uses the token as an access key for a specific resource or action, an attacker can analyze received tokens, predict the next value, and gain access to another user's session and privileges.
This potential vulnerability can be fixed by using a cryptographically secure random number generator:
SecureRandom secureRandom = new SecureRandom();
long token = secureRandom.nextLong() & Long.MAX_VALUE;
HttpCookie cookie = new HttpCookie("token", Long.toString(token));
Built-in features provided by the frameworks you work with should also be used, as they eliminate the need to generate such tokens manually.
This diagnostic rule is classified as:
|
Was this page helpful?
Your message has been sent. We will email you at
If you do not see the email in your inbox, please check if it is filtered to one of the following folders: