Add 88 new defect entries to HIGH and MEDIUM tables:
HIGH: mysql-0001/0002, mariadb-0001, redis-0001/0002, valkey-0001/0002, openvpn-0001,
vlc-0001, prometheus-0001, otel-collector-0001, cockroachdb-0001..0004,
tidb-0001..0008, kubernetes-0001/0002, go-0001, kotlin-0002, scala-0001,
allegro5-0001, sdl2-0001, grafana-0001, clickhouse-0001, duckdb-0001,
mongodb-0001, envoy-0001, istio-0001, cilium-0001, linkerd2-0001,
linux-0001/0002/0003, tor-0002/0003, curl-0001, julia-0001, lua-0001,
perl5-0001, nats-0001, spring-0003/0004, tomcat-0001, onos-0002, odl-0002
MEDIUM: helm-0001, mariadb-0002, openssl-0001/0002, memcached-0001,
cassandra-0001..0004, flink-0001, storm-0001/0002, zookeeper-0001..0003,
pip-0001, gradle-0001, nginx-0001, haproxy-0001, caddy-0001, varnish-0001,
ffmpeg-0001, gstreamer-0001, raylib-0001, love2d-0001, php-0001/0002,
r-source-0001, cpython-0002, ruby-0001, rabbitmq-0003/0004, activemq-0001,
ovs-0001, onos-0003, odl-0002, jetty-0001
PDF: 976K
46 lines
2.1 KiB
Diff
46 lines
2.1 KiB
Diff
From 0000001 Mon Sep 17 00:00:00 2001
|
||
Subject: [PATCH] CWE-407: jetty-0001 — fix O(V×M) List.contains() in
|
||
HttpFields.formatCsvExcludingExisting()
|
||
|
||
formatCsvExcludingExisting() iterates over V incoming values and calls
|
||
existing.getValues().contains() on each. getValues() returns ArrayList<String>,
|
||
so each lookup is O(M) where M is the existing value count. Total O(V×M).
|
||
|
||
Fix: convert existing values to a HashSet<String> once before the loop,
|
||
replacing O(M) per-iteration with O(1).
|
||
|
||
CWE: CWE-407 (Inefficient Algorithmic Complexity)
|
||
Severity: MEDIUM
|
||
---
|
||
.../eclipse/jetty/http/HttpFields.java | 8 ++++++--
|
||
1 file changed, 6 insertions(+), 2 deletions(-)
|
||
|
||
diff --git a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
index aaaaaaa..bbbbbbb 100644
|
||
--- a/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
+++ b/jetty-core/jetty-http/src/main/java/org/eclipse/jetty/http/HttpFields.java
|
||
@@ -14,6 +14,7 @@ import java.util.ArrayList;
|
||
import java.util.EnumSet;
|
||
import java.util.Iterator;
|
||
import java.util.List;
|
||
+import java.util.HashSet;
|
||
+import java.util.Set;
|
||
|
||
@@ -1576,11 +1577,14 @@ public interface HttpFields extends Iterable<HttpField>
|
||
private static String formatCsvExcludingExisting(QuotedCSV existing, String... values)
|
||
{
|
||
boolean add = true;
|
||
if (existing != null && !existing.isEmpty())
|
||
{
|
||
add = false;
|
||
+ // Build a O(1)-lookup set from existing values once, rather than
|
||
+ // calling ArrayList.contains() — O(M) — on every iteration.
|
||
+ Set<String> existingSet = new HashSet<>(existing.getValues());
|
||
for (int i = values.length; i-- > 0; )
|
||
{
|
||
String unquoted = QuotedCSV.unquote(values[i]);
|
||
- if (existing.getValues().contains(unquoted))
|
||
+ if (existingSet.contains(unquoted))
|
||
values[i] = null;
|
||
else
|
||
add = true;
|