Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Exclude vulnerable snakeyaml from Schema Registry #804

Open
wants to merge 2 commits into
base: master
Choose a base branch
from
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -72,6 +72,11 @@ subprojects {
strictly project.versions_slf4j
}
}
compile(libraries.snakeyaml) {
version {
strictly project.versions_snakeyaml
}
}
compile(libraries.swagger) {
version {
strictly project.versions_swagger
Expand Down
2 changes: 1 addition & 1 deletion dependencies.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -68,7 +68,6 @@ ext.libraries = [
annotations : "com.fasterxml.jackson.core:jackson-annotations",
core : "com.fasterxml.jackson.core:jackson-core",
databind : "com.fasterxml.jackson.core:jackson-databind",
dataformat : "com.fasterxml.jackson.dataformat:jackson-dataformat-yaml",
dataformat_csv : "com.fasterxml.jackson.dataformat:jackson-dataformat-csv",
dataformat_yaml: "com.fasterxml.jackson.dataformat:jackson-dataformat-yaml",
datatype_json_org : "com.fasterxml.jackson.datatype:jackson-datatype-json-org",
Expand Down Expand Up @@ -180,6 +179,7 @@ ext.libraries = [
mysql8 : "mysql:mysql-connector-java:8.0.32",

servlet_api : "javax.servlet:servlet-api:$versions_servlet_api",
snakeyaml : "org.yaml:snakeyaml",

validation_api : "javax.validation:validation-api:$versions_validation_api",
validation_api2 : "jakarta.validation:jakarta.validation-api",
Expand Down
2 changes: 1 addition & 1 deletion gradle.properties
Original file line number Diff line number Diff line change
Expand Up @@ -52,7 +52,7 @@ versions_plexus_dispatcher = 1.4
versions_pmml = 1.0.22
versions_postgresql=42.4.1
versions_slf4j = 1.7.32
versions_snakeyaml = 1.27
versions_snakeyaml = 1.33
versions_servlet_api = 2.5
versions_validation_api = 1.1.0.Final

Expand Down
1 change: 0 additions & 1 deletion registry-common-client/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -27,7 +27,6 @@ gversion {
dependencies {

compile libraries.jackson.databind
compile libraries.jackson.dataformat

compile libraries.logging.slf4j_api

Expand Down
4 changes: 1 addition & 3 deletions registry-common/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -26,9 +26,7 @@ dependencies {
compile libraries.jackson.core
compile libraries.jackson.databind
compile libraries.jackson.annotations
compile libraries.jackson.dataformat_yaml
compile libraries.jackson.mapper


compile libraries.libphonenumber

compile libraries.jaxb_api
Expand Down
5 changes: 3 additions & 2 deletions schema-registry/schema-registry-client/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -24,10 +24,10 @@ dependencies {
compile("com.fasterxml.jackson.datatype:jackson-datatype-joda")
compile("com.fasterxml.jackson.datatype:jackson-datatype-jsr310")
compile("com.fasterxml.jackson.module:jackson-module-parameter-names")
compile("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml")
compile("com.fasterxml.jackson.core:jackson-annotations")

constraints {
compile("org.yaml:snakeyaml") { version { strictly project.versions_snakeyaml } }
compile("com.fasterxml.jackson.core:jackson-core") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.core:jackson-databind") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.datatype:jackson-datatype-json-org") { version { strictly project.versions_jackson2 } }
Expand All @@ -36,10 +36,11 @@ dependencies {
compile("com.fasterxml.jackson.datatype:jackson-datatype-joda") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.datatype:jackson-datatype-jsr310") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.module:jackson-module-parameter-names") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.core:jackson-annotations") { version { strictly project.versions_jackson2 } }
}

compile libraries.snakeyaml

compile(project(':schema-registry:schema-registry-common')) {
exclude group: 'javax.validation', module: 'validation-api'
exclude group: 'com.fasterxml.jackson.core'
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -106,6 +106,8 @@
import com.hortonworks.registries.shaded.javax.ws.rs.client.WebTarget;
import com.hortonworks.registries.shaded.javax.ws.rs.core.MediaType;
import com.hortonworks.registries.shaded.javax.ws.rs.core.Response;
import org.yaml.snakeyaml.constructor.SafeConstructor;

import java.io.File;
import java.io.FileInputStream;
import java.io.IOException;
Expand Down Expand Up @@ -231,7 +233,7 @@ public SchemaRegistryClient(File confFile) throws IOException {
@SuppressWarnings("unchecked")
private static Map<String, ?> buildConfFromFile(File confFile) throws IOException {
try (FileInputStream fis = new FileInputStream(confFile)) {
return (Map<String, Object>) new Yaml().load(IOUtils.toString(fis, StandardCharsets.UTF_8));
return new Yaml(new SafeConstructor()).load(IOUtils.toString(fis, StandardCharsets.UTF_8));
}
}

Expand Down
1 change: 0 additions & 1 deletion schema-registry/schema-registry-serdes/build.gradle
Original file line number Diff line number Diff line change
Expand Up @@ -32,7 +32,6 @@ dependencies {
compile("com.fasterxml.jackson.datatype:jackson-datatype-joda") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.datatype:jackson-datatype-jsr310") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.module:jackson-module-parameter-names") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.dataformat:jackson-dataformat-yaml") { version { strictly project.versions_jackson2 } }
compile("com.fasterxml.jackson.core:jackson-annotations") { version { strictly project.versions_jackson2 } }
compile("org.glassfish.jersey.media:jersey-media-json-jackson") { version { strictly project.versions_jersey2 } }
compile("org.glassfish.jersey.core:jersey-common") { version { strictly project.versions_jersey2 } }
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -22,6 +22,7 @@
import com.hortonworks.registries.schemaregistry.webservice.LocalSchemaRegistryServer;
import org.apache.commons.io.IOUtils;
import org.yaml.snakeyaml.Yaml;
import org.yaml.snakeyaml.constructor.SafeConstructor;

import java.io.FileInputStream;
import java.net.URISyntaxException;
Expand Down Expand Up @@ -102,7 +103,7 @@ private Map<String, Object> createClientConf() {
return ret;
}
try (FileInputStream fis = new FileInputStream(schemaRegistryTestConfiguration.getClientYAMLPath())) {
Map<String, Object> ret = new Yaml().load(IOUtils.toString(fis, StandardCharsets.UTF_8));
Map<String, Object> ret = new Yaml(new SafeConstructor()).load(IOUtils.toString(fis, StandardCharsets.UTF_8));
ret.put("schema.registry.url", registryURL);
return ret;
} catch (Exception e) {
Expand Down