CWE-492: Use of Inner Class Containing Sensitive Data
Inner classes are translated into classes that are accessible at package scope and may expose code that the programmer intended to keep private to attackers.
How it's found
Use of Inner Class Containing Sensitive Data is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
Inner classes quietly introduce several security concerns because of the way they are translated into Java bytecode. In Java source code, it appears that an inner class can be declared to be accessible only by the enclosing class, but Java bytecode has no concept of an inner class, so the compiler must transform an inner class declaration into a peer class with package level access to the original outer class. More insidiously, since an inner class can access private fields in its enclosing class, once an inner class becomes a peer class in bytecode, the compiler converts private fields accessed by the inner class into protected fields.
Vulnerable vs. safe
// private member variables of OuterClass
// constructor of OuterClass
// InnerClass is a member inner class of OuterClass
this.memberOne = varOne;this.memberTwo = varTwo;
this.innerMemberOne = innerVarOne;
// InnerClass has access to private member variables of OuterClass
System.out.println("Value of memberOne is: " + memberOne);return OuterClass.this.memberTwo + separator + this.innerMemberOne;private String innerMemberOne;public InnerClass(String innerVarOne) {}public String concat(String separator) {}private String memberOne;private String memberTwo;public OuterClass(String varOne, String varTwo) {}private class InnerClass {}public class OuterClass {}// private member variables of OuterClass
// constructor of OuterClass
// InnerClass is a static inner class of OuterClass
this.memberOne = varOne;this.memberTwo = varTwo;
this.innerMemberOne = innerVarOne;
// InnerClass only has access to static member variables of OuterClass
return memberTwo + separator + this.innerMemberOne;private String innerMemberOne;public InnerClass(String innerVarOne) {}public String concat(String separator) {}private String memberOne;private static String memberTwo;public OuterClass(String varOne, String varTwo) {}private static class InnerClass {}public class OuterClass {}Consequences
- Read Application Data: "Inner Classes" data confidentiality aspects can often be overcome.
Mitigations
- Implementation: Using sealed classes protects object-oriented encapsulation paradigms and therefore protects code from being extended in unforeseen ways.
- Implementation: Inner Classes do not provide security. Warning: Never reduce the security of the object from an outer class, going to an inner class. If an outer class is final or private, ensure that its inner class is private as well.
Where this fits in a TurboPentest engagement
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Frequently asked questions
What is CWE-492?
Inner classes are translated into classes that are accessible at package scope and may expose code that the programmer intended to keep private to attackers.
How do you find Use of Inner Class Containing Sensitive Data?
Use of Inner Class Containing Sensitive Data is a specific, narrowly defined instance of a broader pattern. Testers confirm it with targeted code review and a proof-of-concept input that exercises the exact code path this weakness describes.
What is the impact of CWE-492?
Read Application Data: "Inner Classes" data confidentiality aspects can often be overcome.
Does TurboPentest test for Use of Inner Class Containing Sensitive Data?
TurboPentest's agentic pentest is powerful and covers a broad range of issues automatically. This particular class is best confirmed in a manual IntegSec engagement, where human pentesters apply deeper methodology and a larger context window than any automated pass.
Related CWEs
Find these issues before an attacker does
TurboPentest runs an agentic AI pentest against your target and reports findings with proof, from $99 per target.
Start a $99 pentest