Insecure deserialization In com.fasterxml.jackson.core:jackson-databind
Description
jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy
Summary
For Java Records, POJOPropertiesCollector._removeUnwantedIgnorals() records a @JsonIgnore-annotated component under its original implicit name before _renameUsing() applies the PropertyNamingStrategy. After the rename, _ignoredPropertyNames still holds only the pre-rename name, so _ignorableProps is built from the stale key. The renamed JSON key passes IgnorePropertiesUtil.shouldIgnore() and is assigned to the Record's constructor parameter, defeating the @JsonIgnore.
Impact
A Record using a naming strategy that relies on @JsonIgnore to keep an internal/privileged component out of deserialization can have that component set from the wire via its renamed key (e.g. a role/flag controlled by an untrusted client).
Affected / Patched (verified via git tag --contains)
2.15-2.18 line: >= 2.15.0, < 2.18.8 -> fixed in 2.18.8 (backport c7c6783)
2.19-2.21 line: >= 2.19.0, < 2.21.4 -> fixed in 2.21.4
3.x line: >= 3.0.0, < 3.1.4 -> fixed in 3.1.4 (#5974, baa2cdf)
Severity / CWE
Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345.
Credits
Omkhar Arasaratnam (@omkhar) - finder.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
maven | 2.18.8, 2.21.4 | ||
maven | 3.1.4 | ||
rpm rhel9 | - | - |
Aliases
References