Maven · com.fasterxml.jackson.core:jackson-databind
jackson-databind has a @JsonView bypass for unwrapped creator parameters
UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active.
View-restricted unwrapped creator parameters can be set from untrusted input where @JsonView is used as a write-side authorization boundary.
git tag --contains)>= 2.21.0, < 2.21.4 -> fixed in 2.21.4 (backport 721fa07, #5973)>= 3.0.0, < 3.1.4 -> fixed in 3.1.4 (#5971, d633bc0)Maintainer: minor. Reporter: HIGH. CWE-863 (Incorrect Authorization); related CWE-284.
Omkhar Arasaratnam (@omkhar) - finder.
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repoSources: CISA KEV (public domain), OSV.dev & GitHub Advisory Database (CC-BY-4.0), FIRST EPSS, NVD/CWE (public domain). Served live from the Stateward advisory database.