Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3pjw-73gf-8qr5

Опубликовано: 21 июл. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

jackson-databind: @JsonIgnore on a Record property is bypassed with a PropertyNamingStrategy

Summary

For Java Records, POJOPropertiesCollector._removeUnwantedIgnorals() records a @JsonIgnore-annotated component under its original implicit name before _renameUsing() applies the PropertyNamingStrategy. After the rename, _ignoredPropertyNames still holds only the pre-rename name, so _ignorableProps is built from the stale key. The renamed JSON key passes IgnorePropertiesUtil.shouldIgnore() and is assigned to the Record's constructor parameter, defeating the @JsonIgnore.

Impact

A Record using a naming strategy that relies on @JsonIgnore to keep an internal/privileged component out of deserialization can have that component set from the wire via its renamed key (e.g. a role/flag controlled by an untrusted client).

Affected / Patched (verified via git tag --contains)

  • 2.15-2.18 line: >= 2.15.0, < 2.18.8 -> fixed in 2.18.8 (backport c7c6783)
  • 2.19-2.21 line: >= 2.19.0, < 2.21.4 -> fixed in 2.21.4
  • 3.x line: >= 3.0.0, < 3.1.4 -> fixed in 3.1.4 (#5974, baa2cdf)

Severity / CWE

Maintainer: minor. Reporter: Moderate. CWE-915; related CWE-345.

Credits

Omkhar Arasaratnam (@omkhar) - finder.

Пакеты

Наименование

com.fasterxml.jackson.core:jackson-databind

maven
Затронутые версииВерсия исправления

>= 2.15.0, < 2.18.8

2.18.8

Наименование

com.fasterxml.jackson.core:jackson-databind

maven
Затронутые версииВерсия исправления

>= 2.19.0, < 2.21.4

2.21.4

Наименование

tools.jackson.core:jackson-databind

maven
Затронутые версииВерсия исправления

>= 3.0.0, < 3.1.4

3.1.4

EPSS

Процентиль: 16%
0.00247
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-915

Связанные уязвимости

CVSS3: 6.5
ubuntu
20 дней назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 6.5
redhat
20 дней назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 6.5
nvd
20 дней назад

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.15.0 until 2.18.8, 2.21.4, and 3.1.4, Java Records using a PropertyNamingStrategy can bypass @JsonIgnore because POJOPropertiesCollector._removeUnwantedIgnorals() records an ignored component under its original implicit name before _renameUsing() applies the naming strategy, allowing the renamed JSON key to be assigned to the Record constructor parameter. This issue is fixed in versions 2.18.8, 2.21.4, and 3.1.4.

CVSS3: 6.5
debian
20 дней назад

jackson-databind contains the general-purpose data-binding functionali ...

suse-cvrf
16 дней назад

Security update for jackson-annotations, jackson-core, jackson-databind

EPSS

Процентиль: 16%
0.00247
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-915