agentsclimarketplace

Run3 druid jackson parameter mapping fix

Skill cxcscmu/SkillLearnBench/skills/b3-teacher-feedback-gemini-3-flash-preview/fix-security-bug/run3_druid-jackson-parameter-mapping-fix

Securing Jackson deserialization in Druid to prevent user-supplied JSON keys from overriding system-injected security configurations.From its SKILL.md

Install
npx -y skills add cxcscmu/SkillLearnBench --skill run3_druid-jackson-parameter-mapping-fix

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

SKILL.md

1.6 KB, 300 tokens by cl100k_base, as published. Nobody here has run it

  1. Analyze Constructor Annotations: Examine the @JsonCreator constructors of JavaScript-related classes. Locate the JavaScriptConfig parameter.

  2. Identify the Bypass Mechanism: The vulnerability exists because Jackson may map unexpected JSON keys (like the empty string "") to object properties if the mapping is ambiguous. If a JavaScriptConfig parameter is present in a constructor but not strictly bound to a specific property or is incorrectly handled by @JacksonInject, a malicious payload can provide its own "enabled: true" configuration.

  3. Apply Explicit Injection: To fix the mapping, ensure the JavaScriptConfig parameter is purely injected and not mapped from JSON properties.

    • Use @JacksonInject without a corresponding @JsonProperty for the config parameter.
    • If @JsonProperty is present on the config parameter, remove it or ensure it does not conflict with the system injection.
    • Example of a secure pattern:
      @JsonCreator
      public JavaScriptDimFilter(
          @JsonProperty("dimension") String dimension,
          @JsonProperty("function") String function,
          ...
          @JacksonInject JavaScriptConfig config // No @JsonProperty here
      )
      
  4. Audit for Hidden Overrides: Check if the class has a setter for JavaScriptConfig or a public field that Jackson might automatically discover. These must be removed or annotated with @JsonIgnore.

What ships with it

Read from the repository

Just SKILL.md. No reference files, no scripts.

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.