Run3 Locate Jackson Deserialization Entry Points in Druid
Find the exact code locations where user-supplied JSON is deserialized into DimFilter and other security-sensitive objects in Apache Druid's indexing pipeline, to identify where raw input validation must occur before Jackson processes it.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_Locate-Jackson-Deserialization-Entry-Points-in-DruidAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
2.3 KB, 449 tokens by cl100k_base, as published. Nobody here has run it
Locating Jackson Deserialization Entry Points
Search Strategy
-
Find Filter Deserialization
- Search for
readValue.*DimFilteracross the codebase - Search for
objectMapper.readValuein indexing-service module - Search for
transformSpecparsing and filter extraction - Look in
DruidInputSource,InputSourceSampler, andSamplerResource
- Search for
-
Trace the Request Path
- The exploit targets
/druid/indexer/v1/samplerendpoint - Find the corresponding resource handler (likely
SamplerResource.java) - Trace from HTTP request → JSON parsing → object deserialization
- Identify where
spec.dataSchema.transformSpec.filteris deserialized
- The exploit targets
-
Identify the ObjectMapper Configuration
- Find the ObjectMapper instance used for this deserialization
- Check if it has custom deserializers registered
- Locate the default deserialization behavior for filters
Expected Findings
The vulnerable flow should look similar to:
// Somewhere in SamplerResource or InputSourceSampler
String jsonInput = request.getBody(); // Raw JSON from attacker
ObjectMapper mapper = new ObjectMapper();
DataSchema schema = mapper.readValue(jsonInput, DataSchema.class);
// At this point, the empty key "" has already bypassed security
DimFilter filter = schema.getTransformSpec().getFilter();
Key Files to Examine
druid-indexing-service/src/main/java/org/apache/druid/indexing/overlord/sampler/SamplerResource.javadruid-indexing-service/src/main/java/org/apache/druid/indexing/overlord/sampler/InputSourceSampler.javadruid-core/src/main/java/org/apache/druid/segment/transform/TransformSpec.javadruid-core/src/main/java/org/apache/druid/query/filter/DimFilter.java
Validation Approach
Once the entry point is found, the fix must:
- Validate raw JSON string before passing to
ObjectMapper.readValue() - Reject empty keys
""at the input stream level - Prevent bypass of JavaScript security via malformed JSON structures
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.