Skip to content

[#673] Fix ArrayIndexOutOfBoundsException on truncated percent-encoding in LDAP URLs - #676

Merged
vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issues/673-ldapurl-percent-decode
Jul 8, 2026
Merged

vharseko merged 1 commit into
OpenIdentityPlatform:masterfrom
vharseko:issues/673-ldapurl-percent-decode

Conversation

@vharseko

@vharseko vharseko commented Jul 3, 2026

Copy link
Copy Markdown
Member

Fixes #673.

Bug

A percent sign followed by fewer than two hexadecimal digits in an LDAP URL crashed with an uncaught runtime exception instead of producing a decode error. Reproducer from the issue:

Aci.decode(ByteString.valueOfUtf8(
    "(version 3.0; acl \":\"; allow (search) userdn=\"ldap://cn=name%B\"; )"), DN.rootDN());
// java.lang.ArrayIndexOutOfBoundsException at LDAPURL.urlDecode

Two instances of the same defect:

  1. org.opends.server.types.LDAPURL.urlDecode — the bounds check if (i+2 > length) allows i+2 == length, so reading the second hex digit (stringBytes[++i]) overruns the array. Fixed to >= (as proposed in the issue). A truncated sequence now throws DirectoryException(INVALID_ATTRIBUTE_SYNTAX, ERR_LDAPURL_PERCENT_TOO_CLOSE_TO_END), which UserDN.decode already converts into a clean AciException.
  2. org.forgerock.opendj.ldap.LDAPUrl.percentDecoder (SDK) — no bounds check at all: decoded.charAt(srcPos + 1/2) threw StringIndexOutOfBoundsException for "...%" / "...%B". Now throws LocalizedIllegalArgumentException(ERR_LDAPURL_INVALID_HEX_BYTE).

Tests

  • LDAPURLTestCase (server) and LDAPUrlTestCase (SDK): truncated "%" / "%B" cases expect a clean decode error.
  • New UserDNTestCase: the exact ACI reproducer from the issue expects AciException.

All three test classes pass locally (mvn -pl opendj-core test -Dtest=LDAPUrlTestCase; mvn -pl opendj-server-legacy verify -P precommit -Dit.test="LDAPURLTestCase,UserDNTestCase").

…DAP URLs (OpenIdentityPlatform#673)

A percent sign followed by fewer than two hexadecimal digits (e.g. the ACI
userdn "ldap://cn=name%B") crashed instead of producing a decode error:

- org.opends.server.types.LDAPURL.urlDecode: the bounds check allowed i+2 ==
  length, so reading the second hex digit overran the array; use >= so a
  truncated sequence throws INVALID_ATTRIBUTE_SYNTAX, which UserDN.decode
  already converts into a clean AciException.
- org.forgerock.opendj.ldap.LDAPUrl.percentDecoder had no bounds check at all
  and threw StringIndexOutOfBoundsException; throw
  ERR_LDAPURL_INVALID_HEX_BYTE instead.

Tests: truncated "%" / "%B" cases in LDAPURLTestCase (server) and
LDAPUrlTestCase (SDK), plus UserDNTestCase with the ACI reproducer from the
issue.
@vharseko
vharseko requested a review from maximthomas July 3, 2026 09:24
@vharseko vharseko added the bug label Jul 3, 2026
@vharseko vharseko changed the title Fix ArrayIndexOutOfBoundsException on truncated percent-encoding in LDAP URLs (#673) [#673] Fix ArrayIndexOutOfBoundsException on truncated percent-encoding in LDAP URLs Jul 3, 2026
@vharseko
vharseko merged commit e53e018 into OpenIdentityPlatform:master Jul 8, 2026
17 checks passed
@vharseko
vharseko deleted the issues/673-ldapurl-percent-decode branch July 8, 2026 16:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Parsing ACI with userdn containing encoded characters like %B2 are failing in case less then 2 symbols are provided after %

2 participants