Repository navigation
fix(security): bound Jackson fallback cache for TFS bug 712021 - #162
Open
dev-bot-laserfiche wants to merge 1 commit into
Open
dev-bot-laserfiche wants to merge 1 commit into
dev-bot-laserfiche wants to merge 1 commit into
Conversation
Upgrade Jackson databind/core to 2.21.7 within the existing LTS line to bound the polymorphic fallback type-ID cache (CVE-2026-91776). Add regression coverage with the actual client mapper and Entry model. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Contributor
Contributor
integration-test-results-cloud78 tests +1 66 ✅ - 10 3m 43s ⏱️ + 1m 2s For more details on these failures and errors, see this check. Results for commit acd03b1. ± Comparison against base commit 8218848. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of changes: Fix CVE-2026-91776 in the Jackson dependency used by the v2 Repository API client, tracked by TFS bug 712021.
The finding is reachable, not a component-match false positive:
EntryusesJsonTypeInfo.Id.NAMEwithdefaultImpl = Entry.class, and repository responses are deserialized through the reusableTokenClientObjectMapper.EntryType.fromValue()returns null for unknown values rather than rejecting them before polymorphic resolution. A bounded reproduction using that actual mapper and model retained 10,000 cache entries after 10,000 distinct unknownentryTypevalues on 2.21.6, versus one entry when the same value was repeated.Update the shared
jackson-versionproperty from 2.21.6 to 2.21.7. This upgrades jackson-databind and jackson-core together, remains in the existing 2.21 LTS policy, and leaves the separately versioned jackson-annotations at 2.21. Maven Central confirms 2.21.7 is the latest patch in this line. Its upstreamTypeDeserializerBasepatch bounds the type-ID cache to 1,000 entries and skips caching IDs longer than 256 characters. Jackson is used at runtime by the mapper and cannot be removed as an unused dependency. This Maven project has no dependency lockfile.Add four unit regressions using the actual mapper/model: 10,000 distinct versus repeated unknown IDs, overlong IDs, and preservation of all four known subtypes. Update the changelog. Existing PRs 159 and 160 target older Jackson versions and do not address this CVE; merged PR 161 established the current 2.21.6 baseline.
Verification on JDK 8:
mvn -B -q -Dspotless.apply.skip=true -Dtest='com.laserfiche.repository.api.unit.**' clean packagepasses all 29 unit tests and packages successfully. The lifecycle formatter is skipped to avoid unrelated reformatting of existing generated sources.mvn -B -q spotless:check -DspotlessFiles=src/test/java/com/laserfiche/repository/api/unit/EntryDeserializationTest.javapasses.dependency:treeresolves jackson-databind/core 2.21.7 and jackson-annotations 2.21. Live cloud integration tests require CI secrets and were not run locally.Hosted CI: build, all 29 unit tests, and CodeQL pass.
build-n-testandintegration-test-results-cloudare red in the PR run because the live cloud suite reports empty search results, six missing-entry fixture errors, and an invalid/expired access token; cleanup also reports an authentication error. A fresh unchanged v2 baseline run at commit82188486112c77786fe8390cfc82df536130a3a8, still using Jackson 2.21.6, reproduces the same three search failures, six missing-entry errors, and invalid/expired token failure. These main integration failures therefore exist without this change. Documentation and publishing jobs are skipped after the integration failure. No unrelated test/environment changes are included.Work item links