Skip to content

Commit

Permalink
merge main
Browse files Browse the repository at this point in the history
  • Loading branch information
sumitsuthar committed Mar 12, 2025
2 parents a6d2c33 + d61be7e commit 44a511c
Show file tree
Hide file tree
Showing 21 changed files with 1,211 additions and 559 deletions.
36 changes: 36 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,39 @@
### v2.3.2 (2025-03-11)
#### Bug fixes
* Updated axios to v1.8.2
#### Miscellaneous chores
* Updated readme


### v2.3.1 (2025-02-04)
#### Bug fixes
* Removed docker-cli-js dependency and updated mongodb unit test case (#283)
* Added safety check for agentModule before accessing its properties (#284)

### v2.3.0 (2025-02-03)
#### Features
* Added Support for VM module
* IAST support for Next.js
* Support for Insecure settings i.e crypto, hash and random modules

#### Bug fixes
* Fix for special characters in ws header
* Fix for getting transaction in graphql instrumentation
* Fix for mongodb unit tests

#### Miscellaneous chores
* deps-dev: bump undici from v5.28.4 to v5.28.5
* Updated axios to v1.7.9

### v2.2.0 (2024-12-18)
#### Features
* Support for express 5.x
* IAST support for GraphQL
* Added support for trustboundary security events

#### Bug fixes
* Fix for empty route in fastify

### v2.1.1 (2024-11-07)
#### Bug fixes
* Fix for assignment to logger constant
Expand Down
2 changes: 2 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -51,6 +51,7 @@ The [Developer docs](http://newrelic.github.io/node-newrelic/) for writing instr
- `https`
- `fs`
- `child_process`
- `vm`
- [mysql](https://www.npmjs.com/package/mysql)(2.16.x and above)
- [mysql2](https://www.npmjs.com/package/mysql2) (2.x and above)
- [pg](https://www.npmjs.com/package/pg)(7.x and above)
Expand All @@ -68,6 +69,7 @@ The [Developer docs](http://newrelic.github.io/node-newrelic/) for writing instr
- [xpath](https://www.npmjs.com/package/xpath)(0.0.20 and above)
- [xpath.js](https://www.npmjs.com/package/xpath.js)(0.0.1 and above)
- [undici](https://www.npmjs.com/package/undici)(4.7.0 and above)
- [next](https://www.npmjs.com/package/next)(13.4.19 and above)

For more information, please see New Relic Node.js agent [compatibility and requirements](https://docs.newrelic.com/docs/apm/agents/nodejs-agent/getting-started/compatibility-requirements-nodejs-agent/).

Expand Down
24 changes: 3 additions & 21 deletions THIRD_PARTY_NOTICES.md
Original file line number Diff line number Diff line change
Expand Up @@ -59,7 +59,6 @@ code, the source code can be found at [https://github.com/newrelic/csec-node-age
* [eslint-plugin-promise](#eslint-plugin-promise)
* [eslint-plugin-sonarjs](#eslint-plugin-sonarjs)
* [koa](#koa)
* [mongodb-memory-server](#mongodb-memory-server)
* [mongodb](#mongodb)
* [mongodb](#mongodb)
* [mongodb](#mongodb)
Expand All @@ -79,7 +78,7 @@ code, the source code can be found at [https://github.com/newrelic/csec-node-age

### axios

This product includes source derived from [axios](https://github.com/axios/axios) ([v1.7.4](https://github.com/axios/axios/tree/v1.7.4)), distributed under the [MIT License](https://github.com/axios/axios/blob/v1.7.4/LICENSE):
This product includes source derived from [axios](https://github.com/axios/axios) ([v1.8.2](https://github.com/axios/axios/tree/v1.8.2)), distributed under the [MIT License](https://github.com/axios/axios/blob/v1.8.2/LICENSE):

```
# Copyright (c) 2014-present Matt Zabriskie & Collaborators
Expand Down Expand Up @@ -259,7 +258,7 @@ THE SOFTWARE.

### https-proxy-agent

This product includes source derived from [https-proxy-agent](https://github.com/TooTallNate/proxy-agents) ([v7.0.4](https://github.com/TooTallNate/proxy-agents/tree/v7.0.4)), distributed under the [MIT License](https://github.com/TooTallNate/proxy-agents/blob/v7.0.4/LICENSE):
This product includes source derived from [https-proxy-agent](https://github.com/TooTallNate/proxy-agents) ([v7.0.6](https://github.com/TooTallNate/proxy-agents/tree/v7.0.6)), distributed under the [MIT License](https://github.com/TooTallNate/proxy-agents/blob/v7.0.6/LICENSE):

```
(The MIT License)
Expand Down Expand Up @@ -512,7 +511,7 @@ THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLI

### semver

This product includes source derived from [semver](https://github.com/npm/node-semver) ([v7.5.4](https://github.com/npm/node-semver/tree/v7.5.4)), distributed under the [ISC License](https://github.com/npm/node-semver/blob/v7.5.4/LICENSE):
This product includes source derived from [semver](https://github.com/npm/node-semver) ([v7.6.3](https://github.com/npm/node-semver/tree/v7.6.3)), distributed under the [ISC License](https://github.com/npm/node-semver/blob/v7.6.3/LICENSE):

```
The ISC License
Expand Down Expand Up @@ -1874,23 +1873,6 @@ SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
```

### mongodb-memory-server

This product includes source derived from [mongodb-memory-server](https://github.com/nodkz/mongodb-memory-server) ([v8.13.0](https://github.com/nodkz/mongodb-memory-server/tree/v8.13.0)), distributed under the [MIT License](https://github.com/nodkz/mongodb-memory-server/blob/v8.13.0/LICENSE.md):

```
The MIT License (MIT)
Copyright (c) 2017-present Pavel Chertorogov
Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions:
The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software.
THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
```

### mongodb

This product includes source derived from [mongodb](https://github.com/mongodb/node-mongodb-native) ([v2.2.36](https://github.com/mongodb/node-mongodb-native/tree/v2.2.36)), distributed under the [Apache-2.0 License](undefined):
Expand Down
9 changes: 6 additions & 3 deletions lib/instrumentation-security/core/event-constants.js
Original file line number Diff line number Diff line change
Expand Up @@ -14,14 +14,15 @@ const EVENT_TYPE = {
HTTP_REQUEST: 'HTTP_REQUEST',
CODE_INJECTION: 'CODE_INJECTION',
XXE: 'XXE',
CIPHER: 'CIPHER',
HASH: 'HASH',
RANDOM: 'RANDOM',
UNVALIDATED_REDIRECT: 'UNVALIDATED_REDIRECT',
REFLECTED_XSS: 'REFLECTED_XSS',
XPATH: 'XPATH',
LDAP: 'LDAP',
SECURE_COOKIE: 'SECURE_COOKIE'
SECURE_COOKIE: 'SECURE_COOKIE',
TRUSTBOUNDARY: 'TRUSTBOUNDARY',
CRYPTO: 'CRYPTO',
}
const EVENT_CATEGORY = {
MYSQL: 'MYSQL',
Expand All @@ -42,7 +43,9 @@ const EVENT_CATEGORY = {
REFLECTED_XSS: 'REFLECTED_XSS',
XPATH: 'XPATH',
LDAP: 'LDAP',
SECURE_COOKIE: 'SECURE_COOKIE'
SECURE_COOKIE: 'SECURE_COOKIE',
TRUSTBOUNDARY: 'TRUSTBOUNDARY',
CIPHER: 'CIPHER',
}

module.exports = {
Expand Down
145 changes: 145 additions & 0 deletions lib/instrumentation-security/hooks/crypto/nr-crypto.js
Original file line number Diff line number Diff line change
@@ -0,0 +1,145 @@
/*
* Copyright 2023 New Relic Corporation. All rights reserved.
* SPDX-License-Identifier: New Relic Software License v1.0
*/

module.exports = initialize
const requestManager = require('../../core/request-manager');
const secUtils = require("../../core/sec-utils");
const API = require("../../../nr-security-api");
const securityMetaData = require('../../core/security-metadata');
const { EVENT_TYPE, EVENT_CATEGORY } = require('../../core/event-constants');
const { NR_CSEC_FUZZ_REQUEST_ID } = require('../../core/constants');
const logger = API.getLogger();
const NRLIB = 'newrelic/lib';
const SALIB = 'security-agent/lib'

/**
* Entry point of crypto module hook
* @param {*} shim
* @param {*} mod
* @param {*} moduleName
*/
function initialize(shim, mod, moduleName) {
if (API && API.getNRAgent() && API.getNRAgent().config.security.exclude_from_iast_scan.iast_detection_category.insecure_settings) {
logger.warn('insecure_settings detection is disabled');
return;
}
logger.info('Instrumenting ' + moduleName)
cryptoCipherHooks(shim, mod, 'createCipheriv', moduleName);
cryptoHashHmacHooks(shim, mod, 'createHash', moduleName);
cryptoHashHmacHooks(shim, mod, 'createHmac', moduleName);
cryptoRandomHooks(shim, Math, 'random', "Math");
}
/**
* wrapper to hook crypto cipher methods
* @param {*} shim
* @param {*} mod
* @param {*} methodName
* @param {*} moduleName
*/
function cryptoCipherHooks(shim, mod, methodName, moduleName) {
shim.wrap(mod, methodName, function makeWrapper(shim, fn) {
logger.debug(`Instrumenting ${moduleName}.${methodName}`);
return function wrapper() {
const interceptedArgs = [arguments[0]];
shim.interceptedArgs = interceptedArgs;
const request = requestManager.getRequest(shim);
if (request && API.getSecAgent() && API.getSecAgent().status && API.getSecAgent().status.getStatus() === 'active') {
const traceObject = secUtils.getTraceObject(shim);
const secMetadata = securityMetaData.getSecurityMetaData(request, interceptedArgs, traceObject, secUtils.getExecutionId(), EVENT_TYPE.CRYPTO, EVENT_CATEGORY.CIPHER)
if (secMetadata.traceObject && secMetadata.traceObject.stacktrace && (secMetadata.traceObject.stacktrace[0].includes(NRLIB) || secMetadata.traceObject.stacktrace[0].includes(SALIB))) {
//do nothing
}
else {
const secEvent = API.generateSecEvent(secMetadata);
this.secEvent = secEvent;
API.sendEvent(secEvent);
}
}
const result = fn.apply(this, arguments);

if (result && request && request.headers[NR_CSEC_FUZZ_REQUEST_ID]) {
API.generateExitEvent(this.secEvent);
delete this.secEvent
}
return result;
}
})
}


/**
* wrapper to hook crypto hash and mac methods
* @param {*} shim
* @param {*} mod
* @param {*} methodName
* @param {*} moduleName
*/
function cryptoHashHmacHooks(shim, mod, methodName, moduleName) {
shim.wrap(mod, methodName, function makeWrapper(shim, fn) {
logger.debug(`Instrumenting ${moduleName}.${methodName}`);
return function wrapper() {
const interceptedArgs = [arguments[0]];
shim.interceptedArgs = interceptedArgs;
const request = requestManager.getRequest(shim);

if (request && arguments[0] !== 'sha256' && API.getSecAgent() && API.getSecAgent().status && API.getSecAgent().status.getStatus() === 'active') {
const traceObject = secUtils.getTraceObject(shim);
const secMetadata = securityMetaData.getSecurityMetaData(request, interceptedArgs, traceObject, secUtils.getExecutionId(), EVENT_TYPE.HASH, EVENT_CATEGORY.HASH)
if (secMetadata.traceObject && secMetadata.traceObject.stacktrace && (secMetadata.traceObject.stacktrace[0].includes(NRLIB) || secMetadata.traceObject.stacktrace[0].includes(SALIB))) {
//do nothing
}
else {
const secEvent = API.generateSecEvent(secMetadata);
this.secEvent = secEvent;
API.sendEvent(secEvent);
}
}
const result = fn.apply(this, arguments);
if (result && request && request.headers[NR_CSEC_FUZZ_REQUEST_ID] && arguments[0] !== 'sha256') {
API.generateExitEvent(this.secEvent);
delete this.secEvent
}
return result;
}
})
}
/**
* Wrapper for random hooks
* @param {*} shim
* @param {*} mod
* @param {*} methodName
* @param {*} moduleName
*/
function cryptoRandomHooks(shim, mod, methodName, moduleName) {
shim.wrap(mod, methodName, function makeWrapper(shim, fn) {
logger.debug(`Instrumenting ${moduleName}.${methodName}`);
return function wrapper() {
const interceptedArgs = ["Math.random"];
shim.interceptedArgs = interceptedArgs;
const request = requestManager.getRequest(shim);
if (request && API.getSecAgent() && API.getSecAgent().status && API.getSecAgent().status.getStatus() === 'active') {
const traceObject = secUtils.getTraceObject(shim);
const secMetadata = securityMetaData.getSecurityMetaData(request, interceptedArgs, traceObject, secUtils.getExecutionId(), EVENT_TYPE.RANDOM, EVENT_CATEGORY.WEAKRANDOM)
if (secMetadata.traceObject && secMetadata.traceObject.stacktrace && secMetadata.traceObject.stacktrace[0] && (secMetadata.traceObject.stacktrace[0].includes(NRLIB) || secMetadata.traceObject.stacktrace[0].includes(SALIB))) {
//do nothing
}
else {
const secEvent = API.generateSecEvent(secMetadata);
this.secEvent = secEvent;
API.sendEvent(secEvent);
}

}
const result = fn.apply(this, arguments);
if (result && request && request.headers[NR_CSEC_FUZZ_REQUEST_ID]) {
API.generateExitEvent(this.secEvent);
delete this.secEvent
}
return result;
}
})
}


74 changes: 71 additions & 3 deletions lib/instrumentation-security/hooks/express/nr-express.js
Original file line number Diff line number Diff line change
Expand Up @@ -30,12 +30,14 @@ module.exports = function initialize(shim, express) {

if (express.Router.use) {
wrapExpress4(shim, express)
}
}
else if (express.Router.prototype) {
wrapExpress5(shim, express)
}
if(API && API.getNRAgent() && !API.getNRAgent().config.security.exclude_from_iast_scan.iast_detection_category.invalid_file_access){
expressFileHook(shim, express && express.response, 'download')
expressFileHook(shim, express && express.response, 'sendFile')
}

}

/**
Expand Down Expand Up @@ -121,7 +123,7 @@ function extractParams(shim, req) {
* @param {*} mod
* @param {*} fun
*/
function expressFileHook(shim, mod, fun){
function expressFileHook(shim, mod, fun) {
shim.wrap(mod, fun, function makeFAWrapper(shim, fn) {
if (!shim.isFunction(fn)) {
return fn
Expand Down Expand Up @@ -149,4 +151,70 @@ function expressFileHook(shim, mod, fun){
});
}

/**
* Wrapper to hook express version 5.x route method
* @param {*} shim
* @param {*} express
*/
function wrapExpress5(shim, express) {
shim.wrap(express.Router.prototype, 'route', function wrapRoute(shim, fn) {
if (!shim.isFunction(fn)) {
return fn
}
logger.debug('Instrumenting express.Router.prototype.route');
return function wrappedRoute() {
try {
const stakTrace = secUtils.traceElementForRoute();
const splittedStack = stakTrace[0].split(DOUBLE_DOLLAR);
const key = lodash.upperCase(splittedStack[1]) + ATTHERATE + arguments[0];
routeManager.setRoute(key, splittedStack[0]);
} catch (error) {

}
const route = fn.apply(this, arguments)
return route;
}
})

}

module.exports.wrapRouter = function wrapExpress5Router(shim, mod) {
let layer = shim.require('./lib/layer');
shim.wrap(layer.prototype, 'match', function wrapParam(shim, fn) {
if (!shim.isFunction(fn)) {
return fn
}
logger.debug('Instrumenting router.layer.match');
return function wrappedParam() {
const route = fn.apply(this, arguments);

try {
const uri = this.route.path;
const params = this.params;
const transaction = shim.tracer.getTransaction();
if (transaction) {
let request = requestManager.getRequestFromId(transaction.id);
if (params && request) {
Object.keys(params).forEach(function (key) {
if (params[key]) {
if (!request.parameterMap[key]) {
request.parameterMap[key] = new Array(params[key].toString());
requestManager.setRequest(transaction.id, request);
}
}
});
}
if (uri && request) {
request.uri = uri;
requestManager.setRequest(transaction.id, request);
}
}
} catch (error) {
logger.debug("Error while getting path params via router module", error);
}

return route
}
})
}

Loading

0 comments on commit 44a511c

Please sign in to comment.