Guian Gumpac created TINKERPOP-3279:
---------------------------------------

             Summary: GraphSON 1.0 embedded types unsafe deserialization
                 Key: TINKERPOP-3279
                 URL: https://issues.apache.org/jira/browse/TINKERPOP-3279
             Project: TinkerPop
          Issue Type: Bug
          Components: io
    Affects Versions: 4.0.0, 3.7.7, 3.8.2
            Reporter: Guian Gumpac


GraphSON 1.0 with embedded types (`TypeInfo.PARTIAL_TYPES`) configures Jackson 
default typing with `JsonTypeInfo.Id.CLASS` and no `PolymorphicTypeValidator`, 
so reading a document reconstructs whatever class is named in its `@class` 
property.

Affected: gremlin-core GraphSON IO (`GraphSONMapper`), consumed by `io()`, 
`GraphSONReader`, graph persistence, and the typed GraphSON 1.0 wire serializer 
`GraphSONMessageSerializerV1` (`application/vnd.gremlin-v1.0+json`). GraphSON 
1.0 only.

With `Id.CLASS` default typing and no validator, a `@class` value names a 
fully-qualified Java class that Jackson resolves via `Class.forName` and 
instantiates (running its constructor/setters). Reading an untrusted document 
is therefore an unsafe-deserialization sink on a classpath with a usable gadget 
it is arbitrary code execution, and even without one a crafted `@class` forces 
class loading and static-initializer execution of any class on the classpath. 



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to