[
https://issues.apache.org/jira/browse/TINKERPOP-3279?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18107670#comment-18107670
]
ASF GitHub Bot commented on TINKERPOP-3279:
-------------------------------------------
kenhuuu commented on PR #3586:
URL: https://github.com/apache/tinkerpop/pull/3586#issuecomment-5406143935
Some potential missing test cases:
1. Try cloning a GraphSONMapper to see if the allowedTypeIdPrefixes are
copied over.
2. Test some invalid prefixes like null, empty and blank. Also make sure
something like `com.example` doesn't allow something like
`com.exampleextendedddddddd` through.
3. Add some test for the MessageSerializers or IO serializers and not just
the ObjectMapper directly.
> GraphSON 1.0 embedded types unsafe deserialization
> --------------------------------------------------
>
> Key: TINKERPOP-3279
> URL: https://issues.apache.org/jira/browse/TINKERPOP-3279
> Project: TinkerPop
> Issue Type: Bug
> Components: io
> Affects Versions: 4.0.0, 3.7.7, 3.8.2
> Reporter: Guian Gumpac
> Priority: Major
>
> GraphSON 1.0 with embedded types (`TypeInfo.PARTIAL_TYPES`) configures
> Jackson default typing with `JsonTypeInfo.Id.CLASS` and no
> `PolymorphicTypeValidator`, so reading a document reconstructs whatever class
> is named in its `@class` property.
> Affected: gremlin-core GraphSON IO (`GraphSONMapper`), consumed by `io()`,
> `GraphSONReader`, graph persistence, and the typed GraphSON 1.0 wire
> serializer `GraphSONMessageSerializerV1`
> (`application/vnd.gremlin-v1.0+json`). GraphSON 1.0 only.
> With `Id.CLASS` default typing and no validator, a `@class` value names a
> fully-qualified Java class that Jackson resolves via `Class.forName` and
> instantiates (running its constructor/setters). Reading an untrusted document
> is therefore an unsafe-deserialization sink on a classpath with a usable
> gadget it is arbitrary code execution, and even without one a crafted
> `@class` forces class loading and static-initializer execution of any class
> on the classpath.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)