4 ms·
I love and prefer Java & Static languages too, however saying it cannot happen in a static language is a bit of stretch. The recent Log4j vulnerability and coun
by CSDude 4y ago
I love and prefer Java & Static languages too, however saying it cannot happen in a static language is a bit of stretch. The recent Log4j vulnerability and countless Jackson vulnerabilities are examples of how a simple deserialiation can gone wrong.
Jackson can accept "@class": "com.package.something.Class" which might be class that executes commands on constructor, there is a huge denylist to keep you safe when you use that feature. Almost similar to what Gitlab have here.
- lolinder 4y agoLog4J was not a case of "simple" deserialization. The feature that caused the vulnerability was designed for remote execution of code. For this reason I called it out explicitly as an exception. Vulnerabilities in the serialization library are a separate class of bug. This gitlab bug wasn't a serialization vulnerability, it was a flawed assumption about the structure of the data. The serializer did its job just fine. In the case of Jackson's @class tagging, the key thing is that Java will still force you to think about the type. If you expect the `id` field to be an integer, you'll have to eventually cast Object to the class that you think you have, and that cast will fail if you got something else instead. There's no way for a redis command to make its way into an int field.