漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Vulnerability Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不完整的黑名单
Vulnerability Title
FasterXML jackson-databind 输入验证错误漏洞
Vulnerability Description
FasterXML jackson-databind是FasterXML组织开源的其中的一个具有数据绑定功能的组件。 FasterXML jackson-databind存在输入验证错误漏洞,该漏洞源于BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()方法仅基于clazz.isArray()对数组类型进行白名单验证,而未验证数组组件(元素)类型,导致即使EvilType未在白名单中也可被绕过,当Jackson反序列化元素且无元素类型I
CVSS Information
N/A
Vulnerability Type
N/A