Description
In legacy Java environments using a Security Manager, granting untrusted code RuntimePermission("createClassLoader") or ReflectPermission("suppressAccessChecks") may weaken intended restrictions. Creating a permission object or adding it to a local Permissions collection does not itself grant global permissions. Check how the collection is applied to the actual policy.
The Security Manager has been permanently disabled since JDK 24. Do not rely on this permission list to isolate applications on current JDKs.
Potential impact
- Excessive permissions in an effective policy may allow untrusted code to create class loaders or suppress reflection access checks.
- The impact depends on the executing code, other permissions and module access restrictions.
Remediation
- Remove unnecessary
createClassLoaderandsuppressAccessCheckspermissions from legacy policies. - Grant required permissions only to reviewed code and within the minimum necessary scope.
- Isolate untrusted code using separate processes and operating-system permissions and isolation controls.
Examples
These examples only construct a permission collection. They do not connect it to a policy or enable the Security Manager on JDK 24 or later.
Before
import java.lang.RuntimePermission;
import java.lang.reflect.ReflectPermission;
import java.security.PermissionCollection;
import java.security.Permissions;
public class InsecurePermission {
public static void main(String[] args) {
PermissionCollection permissions = new Permissions();
// Add broad permissions
permissions.add(new RuntimePermission("createClassLoader"));
permissions.add(new ReflectPermission("suppressAccessChecks"));
}
}
After
import java.security.PermissionCollection;
import java.security.Permissions;
public class SecurePermission {
public static void main(String[] args) {
PermissionCollection permissions = new Permissions();
// Do not add these unnecessary permissions
}
}
Explanation:
- Before: Adds permissions to create class loaders and suppress reflection access checks.
- After: Does not add those permissions. The actual restrictions depend on the legacy policy that uses the collection.