【安全】WxPayValidator 未校验微信支付 V3 应答时间戳(Wechatpay-Timestamp),缺少重放攻击防护
Les mainteneurs répondent en général sous 1 jour
Personne n'a encore pris cette issue.
Évaluation
- Difficulté
- 3/5
- Temps estimé
- 1-2 jours
- Accessibilité débutants
- 68/100
Piste de recherche
Start with weixin-java-pay/src/main/java/com/github/binarywang/wxpay/v3/auth/WxPayValidator.java, especially validate(CloseableHttpResponse), and trace its call from SignatureExec.executeWithSignature. Verify the timestamp freshness behavior against the stated five-minute requirement and check the handling of non-JSON 2xx responses; the work is done when expired responses are rejected while valid signed responses remain accepted.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Description
【微信支付 V3】WxPayValidator 未校验应答时间戳,缺少重放攻击防护(Wechatpay-Timestamp 未做新鲜度校验)
漏洞类型:重放攻击防护缺失
影响组件:weixin-java-pay/WxPayValidator
风险场景:链路窃听、中间人重放合法应答
1. 环境
| 项目 | 内容 |
|---|---|
| SDK 版本 | binarywang/WxJava develop 分支(4.8.x 范围内),含 WxPayValidator 的所有已发布 4.x 版本均受影响 |
| 模块 | weixin-java-pay |
| Java 版本 | JDK 8+ |
| 接入方式 | 微信支付 V3(WxPayService + AutoUpdateCertificatesVerifier / CertificatesVerifier,WxPayV3HttpClientBuilder 构建的 CloseableHttpClient) |
2. 复现步骤
- 按官方方式初始化微信支付 V3 的
WxPayService,使用WxPayV3HttpClientBuilder拿到HttpClient(内部通过SignatureExec对 2xx 应答做WxPayValidator.validate)。 - 调用任意 V3 接口(如“查询订单”),正常拿到应答。
- 攻击者截获该次应答,包含:
Wechatpay-TimestampWechatpay-NonceWechatpay-SignatureWechatpay-Serial- JSON body
- 在数分钟、数小时或任意时间后,将此应答原样重放给调用方,或由链路上的中间人重放。
3. 期望行为
依据微信支付 V3 签名验证规范,商户侧应校验 Wechatpay-Timestamp 与本地时间之差不超过 5 分钟;超时的应答应判定为验签失败,以提供重放攻击防护。
4. 实际行为
WxPayValidator.validate(...) 只校验四个头部是否存在,并做密码学验签,从不校验时间戳新鲜度。
方法内明确留有:
// todo: check timestamp
但未实现。
因此,重放的旧应答仍被判定为验签通过,SignatureExec 不会抛出异常,调用方拿到被重放的数据。
5. 根因分析
- 文件:
weixin-java-pay/src/main/java/com/github/binarywang/wxpay/v3/auth/WxPayValidator.java - 方法:
validate(CloseableHttpResponse response)(约第 27–34 行) - 相关代码:
// todo: check timestamp
if (timestamp == null || nonce == null || serialNo == null || sign == null) {
return false;
}
String message = buildMessage(response);
return verifier.verify(serialNo.getValue(), message.getBytes(StandardCharsets.UTF_8), sign.getValue());
- 原因:
verifier.verify(...)仅使用平台证书对timestamp\nnonce\nbody\n做 RSA 验签。- 时间戳本身被当作“参与签名的字符串”,而不是“需校验的时间量”。
- 缺失类似
|当前秒 - Long.parseLong(timestamp)| <= 300的新鲜度判断,导致重放攻击防护缺位。
6. 影响
在存在链路窃听或中间人的场景下,合法应答可被重放并被判为有效,违反微信支付 V3 防重放要求。
同时,validate 对 Content-Type 非 application/json 的 2xx 应答直接 return true 跳过验签(同方法首行),进一步放大风险。
7. 建议修复方向
在 validate 中补充时间戳新鲜度校验,例如:
long wechatTimestamp = Long.parseLong(timestamp.getValue());
long diff = Math.abs(System.currentTimeMillis() / 1000 - wechatTimestamp);
if (diff > 300) {
log.warn("微信支付应答时间戳超时,疑似重放攻击:{} 秒", diff);
return false;
}
并建议将首行的“非 JSON 直接 return true”改为:
- 对未知或非 JSON 的 2xx 应答默认拒绝;或
- 至少记录告警,避免绕过验签。
8. 参考
- 微信支付 V3 签名验证规范:应答/回调需校验
Wechatpay-Timestamp与本地时间差不超过 5 分钟,防止重放。 - 相关代码路径:
SignatureExec.executeWithSignature(...)->validator.validate(response)。
- Langage dominant
- Java
- Étoiles
- 33.1k
- Forks
- 9.1k
- Merge moyen
- 3 j 11 h
- PR mergées (30 j)
- 10
Préparer son environnement
- Aucun Dockerfile ni fichier Docker Compose
- Aucun modèle de pull request
- Lire le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Autres issues de binarywang/WxJava
-
微信支付功能增加对支付品牌的支持Ouverte
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 28/100
binarywang/WxJava#3972 ·
Les mainteneurs répondent en général sous 1 jour
-
欢迎贡献过代码的朋友加入微信开发组专群,以便享受多重福利待遇Ouvertepinned
Difficulté 5/5 Plus d'une semaine Accessibilité débutants 1/100
binarywang/WxJava#3057 ·
Les mainteneurs répondent en général sous 1 jour
-
WxJava 应用案例收集Peut-être à nouveau libre @binarywang l’a pris il y a 2965 jours, et aucune pull request n’est ouverte. Ouvertepinned
binarywang/WxJava#729 · 84 commentaires · 43 réactions · 1 personne assignée ·
Les mainteneurs répondent en général sous 1 jour
Toutes les issues de binarywang/WxJava
Issues similaires
-
Difficulté 2/5 1-3 heures Accessibilité débutants 85/100
objectionary/eo-graphs#80 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 74/100
-
enhancement good first issue
Difficulté 2/5 Une demi-journée Accessibilité débutants 66/100
apache/fineract-consumer-facing#175 ·
Les mainteneurs répondent en général sous 1 jour
-
[BUG] 订单:会员凭订单号即可取消其他会员的待付款订单(取消接口不校验订单归属)Peut-être pris @dadiyang l’a pris aujourd’hui. Ouverte
Difficulté 2/5 1-3 heures Accessibilité débutants 70/100
macrozheng/mall#1016 ·
-
Difficulté 2/5 1-3 heures Accessibilité débutants 78/100