im47cn commented on PR #6531: URL: https://github.com/apache/shenyu/pull/6531#issuecomment-5201772672
Thanks @Aias00 — your points on IV reuse and missing authentication were spot on. Rather than documenting the risk, this push closes it. All three items addressed: **1. CBC IV reuse (CWE-329) → resolved by switching to GCM.** AES and SM4 now use `AES/GCM/NoPadding` / `SM4/GCM/NoPadding` with a fresh 96-bit `SecureRandom` nonce per message and a 128-bit tag. Output is `base64(nonce ‖ ciphertext ‖ tag)`, so the nonce is unique per message — no fixed IV to reuse. The `base64(secret):base64(iv)` key form is gone (GCM must never reuse a fixed IV); the key is now just `base64(secret)`, and the legacy `secret:iv` form is explicitly rejected with a clear error. **2. CBC malleability (CWE-1204) → resolved by GCM's authentication tag.** Any in-transit modification now fails decryption (`AEADBadTagException`) instead of silently producing corrupted plaintext. New tests assert both properties: `shouldEmitDifferentCiphertextForRepeatedEncrypts` (nonce freshness) and `shouldFailAuthenticationWhenCiphertextIsTampered` (integrity). **3. Base64 encoder/decoder asymmetry → fixed.** Unified to `getEncoder()`/`getDecoder()` throughout; `decrypt` now decodes UTF-8 explicitly. **RSA — PKCS#1 v1.5 → OAEP, with a PKCS#1 fallback for your non-regression concern.** To address the padding-oracle weakness without breaking external peers that only speak PKCS#1 v1.5: - The default `rsa` strategy is now `RSA/ECB/OAEPWithSHA-256AndMGF1Padding`, with an explicit `OAEPParameterSpec` (MGF1 also SHA-256) so the transformation is identical across JDKs/providers. - A new **`rsa-pkcs1`** strategy keeps PKCS#1 v1.5 — any rule interoperating with a legacy/external PKCS#1 system can opt in by strategy name, with no code change and no surprise breakage. Shared RSA logic is factored into `AbstractRsaStrategy`; `AbstractCbcCryptorStrategy` is removed. **Note:** RSA test fixtures moved from 512-bit to 2048-bit — OAEP/SHA-256 physically cannot encrypt any plaintext under a 512-bit key (`keyBytes − 2·32 − 2 < 0`), so the old fixture is no longer usable. AES/SM4 round-trip tests cover CJK + JSON payloads. The full cryptor module suite (40 tests) is green locally (main project install + integrated-test test-compile both pass), including the SPI-wiring path you flagged earlier. Would appreciate another look when you have time. -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
