[
https://issues.apache.org/jira/browse/KYLIN-6092?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18105511#comment-18105511
]
ASF GitHub Bot commented on KYLIN-6092:
---------------------------------------
pjfanning commented on PR #2354:
URL: https://github.com/apache/kylin/pull/2354#issuecomment-5325529359
Change looks promising.
There are other places where new ObjectMappers are created. Are we sure that
the changes in this PR are the only ones that need the
PolymorphicTypeValidator?
https://github.com/search?q=repo%3Aapache%2Fkylin+new+ObjectMapper&type=code
Not all of the mappers in the search results are test cases.
> Insecure Jackson deserialization
> --------------------------------
>
> Key: KYLIN-6092
> URL: https://issues.apache.org/jira/browse/KYLIN-6092
> Project: Kylin
> Issue Type: Task
> Reporter: PJ Fanning
> Assignee: Longfei Jiang
> Priority: Major
>
> [https://github.com/apache/kylin/blob/b5b94b51abaf83d68088e4fcab606d2a6530e54d/src/core-common/src/main/java/org/apache/kylin/common/persistence/event/Event.java#L33]
> `@JsonTypeInfo(use = JsonTypeInfo.Id.CLASS)` – when you deserialize the
> `@class` value that appears in the JSON can be any class name and Jackson
> will load that class and try to create an instance.
> You should add a polymorphic type validator to your ObjectMapper that
> restricts which classes can be loaded at deserialization time.
> https://fasterxml.github.io/jackson-databind/javadoc/2.10/com/fasterxml/jackson/databind/jsontype/BasicPolymorphicTypeValidator.html
>
--
This message was sent by Atlassian Jira
(v8.20.10#820010)