Aias00 opened a new issue, #6635:
URL: https://github.com/apache/shenyu/issues/6635
- Severity: High
- Location:
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java:93-131`
(buggy shared `AtomicInteger initDeep` at `:116-122`); reached via
`MapTypeEnum.java:43-47`/`:107-116`
-
Description:
`replaceJsonNode` walks the JSON tree using a single shared `AtomicInteger
initDeep` that increments whenever *any* entry key equals
`deepKey.get(initDeep.get())`. After descending into the target path `a.b` and
matching the leaf `"b"`, the pointer is left at `size-1` (line 121
`initDeep.set(deepKey.size() - 1)`). Subsequent sibling subtrees at the root
are then visited with `initDeep` still at the leaf level, so any key named
`"b"` inside *any* sibling object also matches `deepKey[leaf]`, increments to
`size`, and gets overwritten with the encrypted/decrypted value. Verified trace
for body `{"a":{"b":1},"c":{"b":2}}` with field path `a.b`: returns
`{"a":{"b":"X"},"c":{"b":"X"}}` — i.e. `c.b` is also encrypted. For multi-field
configs, `MapTypeEnum.map(originalBody, modifiedPairs)` calls `ALL.map` once
per field with a fresh `AtomicInteger(0)`, so each dotted field independently
overwrites every same-named leaf in every sibling subtree.
-
Impact:
Configuring the cryptor to encrypt/decrypt a nested field `x.y` causes every
field named `y` under every sibling object of `x` to be encrypted/decrypted too
— silent data corruption of fields the operator did not intend to touch.
-
Suggested fix:
Do not share mutable depth state across siblings. Descend only along the
matching key and reset/branch the depth per subtree (recurse with a copy of the
depth, or only follow the single matching key and leave all other entries
untouched once the path is exhausted).
-
Confidence: High (verified by manual trace through the algorithm)
- Related existing: none
---
_Identified during the 2026-08-02 deep re-scan; full list in
[`docs/scan2-2026-08-02/00-consolidated-critical-high.md`](docs/scan2-2026-08-02/00-consolidated-critical-high.md)._
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]