CWE-492: Use of Inner Class Containing Sensitive Data
Inner classes are translated into classes that are accessible at package scope and may expose code that the programmer intended to keep private to attackers.
How it's found
Use of Inner Class Containing Sensitive Data is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
Inner classes quietly introduce several security concerns because of the way they are translated into Java bytecode. In Java source code, it appears that an inner class can be declared to be accessible only by the enclosing class, but Java bytecode has no concept of an inner class, so the compiler must transform an inner class declaration into a peer class with package level access to the original outer class. More insidiously, since an inner class can access private fields in its enclosing class, once an inner class becomes a peer class in bytecode, the compiler converts private fields accessed by the inner class into protected fields.
Vulnerable vs. safe
// private member variables of OuterClass
// constructor of OuterClass
// InnerClass is a member inner class of OuterClass
this.memberOne = varOne;this.memberTwo = varTwo;
this.innerMemberOne = innerVarOne;
// InnerClass has access to private member variables of OuterClass
System.out.println("Value of memberOne is: " + memberOne);return OuterClass.this.memberTwo + separator + this.innerMemberOne;private String innerMemberOne;public InnerClass(String innerVarOne) {}public String concat(String separator) {}private String memberOne;private String memberTwo;public OuterClass(String varOne, String varTwo) {}private class InnerClass {}public class OuterClass {}// private member variables of OuterClass
// constructor of OuterClass
// InnerClass is a static inner class of OuterClass
this.memberOne = varOne;this.memberTwo = varTwo;
this.innerMemberOne = innerVarOne;
// InnerClass only has access to static member variables of OuterClass
return memberTwo + separator + this.innerMemberOne;private String innerMemberOne;public InnerClass(String innerVarOne) {}public String concat(String separator) {}private String memberOne;private static String memberTwo;public OuterClass(String varOne, String varTwo) {}private static class InnerClass {}public class OuterClass {}Consequences
- Read Application Data: "Inner Classes" data confidentiality aspects can often be overcome.
Mitigations
- Implementation: Using sealed classes protects object-oriented encapsulation paradigms and therefore protects code from being extended in unforeseen ways.
- Implementation: Inner Classes do not provide security. Warning: Never reduce the security of the object from an outer class, going to an inner class. If an outer class is final or private, ensure that its inner class is private as well.
Where this fits in a TurboPentest engagement
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Frequently asked questions
What is CWE-492?
Inner classes are translated into classes that are accessible at package scope and may expose code that the programmer intended to keep private to attackers.
How do you find Use of Inner Class Containing Sensitive Data?
Use of Inner Class Containing Sensitive Data is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
What is the impact of CWE-492?
Read Application Data: "Inner Classes" data confidentiality aspects can often be overcome.
Does TurboPentest test for Use of Inner Class Containing Sensitive Data?
This weakness is not covered by the automated black-box pentest. IntegSec pentesters cover it in a manual engagement.
Related CWEs
Written and reviewed by
Michel Chamberland - Founder & CEO, IntegSec
CISSP, OSCP, OSCE, CEH, GIAC, CCSK · 20+ years in offensive security
Michel has spent 20+ years on offensive security teams including IBM X-Force Red and Trustwave SpiderLabs, leading penetration tests, red team engagements, and breach response for Fortune 500 customers. He is the founder of IntegSec and the architect of TurboPentest.
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a pentest