Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
jackson-databind: Array subtype allowlist bypass in BasicPolymorphicTypeValidator (allowIfSubTypeIsArray)
Vulnerability Description
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Vulnerability Type
不完整的黑名单
Vulnerability Title
FasterXML jackson-databind 输入验证错误漏洞
Vulnerability Description
FasterXML jackson-databind是FasterXML组织开源的其中的一个具有数据绑定功能的组件。 FasterXML jackson-databind存在输入验证错误漏洞,该漏洞源于BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray()方法仅基于clazz.isArray()对数组类型进行白名单验证,而未验证数组组件(元素)类型,导致即使EvilType未在白名单中也可被绕过,当Jackson反序列化元素且无元素类型I
CVSS Information
N/A
Vulnerability Type
N/A