Run3 druid jackson parameter mapping fix
Securing Jackson deserialization in Druid to prevent user-supplied JSON keys from overriding system-injected security configurations.From its SKILL.md
npx -y skills add cxcscmu/SkillLearnBench --skill run3_druid-jackson-parameter-mapping-fixAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
1.6 KB, 300 tokens by cl100k_base, as published. Nobody here has run it
-
Analyze Constructor Annotations: Examine the
@JsonCreatorconstructors of JavaScript-related classes. Locate theJavaScriptConfigparameter. -
Identify the Bypass Mechanism: The vulnerability exists because Jackson may map unexpected JSON keys (like the empty string
"") to object properties if the mapping is ambiguous. If aJavaScriptConfigparameter is present in a constructor but not strictly bound to a specific property or is incorrectly handled by@JacksonInject, a malicious payload can provide its own "enabled: true" configuration. -
Apply Explicit Injection: To fix the mapping, ensure the
JavaScriptConfigparameter is purely injected and not mapped from JSON properties.- Use
@JacksonInjectwithout a corresponding@JsonPropertyfor the config parameter. - If
@JsonPropertyis present on the config parameter, remove it or ensure it does not conflict with the system injection. - Example of a secure pattern:
@JsonCreator public JavaScriptDimFilter( @JsonProperty("dimension") String dimension, @JsonProperty("function") String function, ... @JacksonInject JavaScriptConfig config // No @JsonProperty here )
- Use
-
Audit for Hidden Overrides: Check if the class has a setter for
JavaScriptConfigor a public field that Jackson might automatically discover. These must be removed or annotated with@JsonIgnore.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.