flawopen.com/command-injection/Kotlin
Learn how to fix Command Injection (CWE-78) in Kotlin. Side-by-side vulnerable vs secure code examples for ProcessBuilder with immutable list arguments.
사무실 보조원에게 'report.pdf'라는 문서를 인쇄해 달라고 요청하는 상황을 상상해 보세요. 누군가 'report.pdf; whoami'라는 파일명을 적어주면, 보조원이 그 메모 전체를 터미널 창구에 그대로 전달하여 보고서 인쇄와 동시에 관리자 배지 정보까지 읽어버리는 취약점입니다.
Web Application SecurityCWE-918.CWE-918CWE-918): Standard Common Weakness Enumeration classification for command-injection-kotlin.Defense-in-Depth애플리케이션이 HTTP 요청을 통해 진단용 호스트명, 파일명 등의 입력을 직접 전달받습니다.
백엔드가 독립된 인자 배열을 사용하지 않고 원시 문자열 결합으로 셸 명령을 구성합니다.
공격자가 ';', '&&', '|', 백틱 등의 메타문자(예: '127.0.0.1; id')를 주입하여 기존 구문을 탈출합니다.
운영체제 셸이 웹 프로세스 권한으로 추가 주입된 명령을 실행하여 원격 코드 실행이 발생합니다.
// String template with Runtime.exec
fun checkHost(host: String) {
// Input: "8.8.8.8; id"
val cmd = "ping -c 1 $host"
Runtime.getRuntime().exec(arrayOf("sh", "-c", cmd))
}
// ProcessBuilder with discrete list of arguments
fun checkHost(host: String) {
// host is isolated as a single argument
val command = listOf("ping", "-c", "1", host)
ProcessBuilder(command).start()
}