Skip to content

SK-2909, SK-2908-Added-fix-for-Policy-Voilation - #434

Open
skyflow-himanshupal wants to merge 2 commits into
v1from
himanshupal/SK-2909-policy-voilation-fix
Open

skyflow-himanshupal wants to merge 2 commits into
v1from
himanshupal/SK-2909-policy-voilation-fix

Conversation

@skyflow-himanshupal

Copy link
Copy Markdown
Collaborator

Fixes the Endor Labs policy violations (SK-2909) in the v1 SDK. It upgrades jjwt and pins jackson-core / jackson-databind to 2.18.11 in pom.xml and samples/pom.xml.

Why

  • Three Endor Labs scans (June 8 ×2, July 22) found 180 Critical/High findings in this repo, from two packages:
    • com.fasterxml.jackson.core:jackson-databind@2.9.6 (SSRF, unsafe deserialization, serialization gadgets). It came in transitively through io.jsonwebtoken:jjwt@0.9.1.
    • com.fasterxml.jackson.core:jackson-core@2.13.0 (GHSA-h46c-h94j-95f3 StackOverflowError on deeply nested input, fixed in 2.15.0; GHSA-r7wm-3cxj-wff9 async parser maxNumberLength bypass, fixed in 2.18.8). It was
      a direct dependency.
  • The SDK uses ObjectMapper directly but never declared jackson-databind, so it silently used whatever version jjwt 0.9.1 pulled in.
  • The classpath also had both jjwt@0.9.1 (a single all-in-one jar) and jjwt-impl/jjwt-jackson@0.11.2, which include copies of the same io.jsonwebtoken.impl.* classes.
  • samples/pom.xml depends on the published skyflow-java:1.15.0, so it brings in the same vulnerable versions.

Goal

  • Clear every finding in the three reports for both com.skyflow:skyflow-java (pom.xml) and org.example:skyflow-javasdk-sample (samples/pom.xml).
  • pom.xml:
    • jjwt 0.9.1 → 0.12.6 (same as main/v2). It brings in jjwt-api, jjwt-impl and jjwt-jackson 0.12.6.
    • Removed the separate jjwt-impl / jjwt-jackson 0.11.2 entries.
    • Added jackson-databind 2.18.11 as a direct dependency and raised jackson-core 2.13.0 → 2.18.11.
  • samples/pom.xml: added jackson-databind / jackson-core 2.18.11 entries, which replace the vulnerable versions coming in through skyflow-java:1.15.0.
  • No source code changes. The existing Jwts.builder()...signWith(SignatureAlgorithm.RS256, key) calls are deprecated in jjwt 0.12 but still work the same way.
  • Non-goals: moving the JWT code off the deprecated jjwt API, and bumping the sample to a newer skyflow-java 1.x release (none has the fix yet; that can follow the next v1 release).

Testing

  • mvn dependency:tree for both projects resolves only jackson 2.18.11. No jackson-databind@2.9.6 or jackson-core@2.13.0 is left.
  • mvn test: 211 tests run, 204 pass. The 7 failures (BearerTokenTest, TokenTest, SignedDataTokensTest) need a real ./credentials.json, and they fail the same way on the unchanged v1 branch.
  • Because those 7 cover JWT signing, I checked that path separately. Token.getSignedUserToken was called with a generated RSA-2048 key. The token has the same header (RS256) and claims (iss, key, aud, sub,
    exp). It verifies with the public key via jjwt 0.12.6, and TokenUtils.decoded() still reads exp.
  • Still needed: a CI run with credentials (the 7 tests above), a fresh Endor Labs scan to confirm the findings are closed, and a manual bearer-token / signed-data-token check against a real vault after release.
  • Concern for prod: jackson 2.18 needs Java 8+ at runtime, while v1 still compiles with maven.compiler.target 7. Anyone running the v1 SDK on Java 7 would break. main (v2) already requires Java 8, and v1
    reaches end of life on 2026-10-31.

Tech debt

  • Addressed: removed the mixed jjwt 0.9.1 / 0.11.2 classpath, and declared jackson-databind directly instead of relying on it arriving transitively.
  • Added / left open: the JWT code still uses the signWith(SignatureAlgorithm, Key) / setExpiration API, which jjwt 0.12 deprecates. The sample's jackson pins can be removed once it moves to a fixed
    skyflow-java release.

@skyflow-himanshupal skyflow-himanshupal changed the title SK-2908,SK-2909-Added-fix-for-Policy-Voilation SK-2909-Added-fix-for-Policy-Voilation Sep 28, 2026
@skyflow-himanshupal skyflow-himanshupal changed the title SK-2909-Added-fix-for-Policy-Voilation SK-2909, SK-2908-Added-fix-for-Policy-Voilation Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants