[
https://issues.apache.org/jira/browse/DRILL-8549?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18099886#comment-18099886
]
ASF GitHub Bot commented on DRILL-8549:
---------------------------------------
cgivre commented on PR #3057:
URL: https://github.com/apache/drill/pull/3057#issuecomment-5111124197
> @cgivre does look like a viable solution or is too risky to add this type
of validation? Classes like StatisticsHolder could in theory wrap any T type.
The PolymorphicTypeValidator that I added here cover the most obvious use cases
but maybe there are some that are not tested in the Drill tests but that users
could be relying on?
I'm honestly not sure. The unit tests all pass which is a good sign. Have
you tried building Drill and testing manually?
> Insecure Jackson deserialization
> --------------------------------
>
> Key: DRILL-8549
> URL: https://issues.apache.org/jira/browse/DRILL-8549
> Project: Apache Drill
> Issue Type: Task
> Reporter: PJ Fanning
> Priority: Major
>
> https://github.com/apache/drill/blob/09ff1949aac7282dafec0f10ae16669b4f7d8c08/exec/java-exec/src/main/java/org/apache/drill/exec/planner/physical/PartitionFunction.java#L27
> `@JsonTypeInfo(use = JsonTypeInfo.Id.CLASS)` – when you deserialize the
> `@class` value that appears in the JSON can be any class name and Jackson
> will load that class and try to create an instance.
> You should add a polymorphic type validator to your ObjectMapper that
> restricts which classes can be loaded at deserialization time.
> [https://fasterxml.github.io/jackson-databind/javadoc/2.10/com/fasterxml/jackson/databind/jsontype/BasicPolymorphicTypeValidator.html]
--
This message was sent by Atlassian Jira
(v8.20.10#820010)