GHSA-gg69-9wwp-6jx2HighCVSS 8.1
Spring for Apache Pulsar: JsonPulsarHeaderMapper Trusted-Package Prefix Check Allows Unintended Subpackage Deserialization
🔗 CVE IDs covered (1)
📋 Description
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-packages configuration fell back to trusting all packages rather than applying a safe default allow-list.
Affected versions: Spring for Apache Pulsar 2.0.0 through 2.0.5; 1.2.0 through 1.2.17; 1.1.0 through 1.1.17.
🎯 Affected products3
- maven/org.springframework.pulsar:spring-pulsar:>= 2.0.0, <= 2.0.5
- maven/org.springframework.pulsar:spring-pulsar:>= 1.2.0, <= 1.2.17
- maven/org.springframework.pulsar:spring-pulsar:<= 1.1.17