Aias00 opened a new issue, #6878:
URL: https://github.com/apache/shenyu/issues/6878

   ## Description
   `parser(String json, String fieldName)` calls 
`GsonUtils.getInstance().toObjectMap(json)` at line 51. The underlying 
deserializer returns `null` whenever the body is not a JSON object (e.g. a JSON 
array `[{...}]`, a primitive, or invalid JSON). `parser` never null-checks 
`map`: (a) non-dotted field path, line 64 `map.get(fieldName)` → NPE; (b) 
dotted field path, line 55 `(JsonObject) map.get(split[0])` → NPE. Even for a 
valid object, the dotted path has no null-safety: line 60 
`jsonObject.getAsJsonObject(split[i])` returns null for a missing/non-object 
intermediate, and the next loop iteration NPEs; line 55 `(JsonObject) 
map.get(split[0])` CCEs when the configured top-level field is present but is a 
primitive/array. These exceptions propagate out of `MapTypeEnum.convert` before 
`AbstractCryptorPlugin.convert` can fall back to `fieldErrorParse`.
   
   ## Location
   - 
`shenyu-plugin/shenyu-plugin-security/shenyu-plugin-cryptor/src/main/java/org/apache/shenyu/plugin/cryptor/utils/JsonUtil.java:50-67`
 (reached via `MapTypeEnum.java:54-55,75,80`; 
`AbstractCryptorPlugin.java:77-83`; `CryptorRequestPlugin.java:54-55`; 
`CryptorResponsePlugin.java:40`)
   
   ## Impact
   Request side: any client can send a JSON-array body (or a body where a 
configured nested prefix is non-object/absent) to a cryptor-protected route and 
trigger an uncaught NPE/CCE → 500 with stack trace (pre-auth). Response side: a 
legitimate upstream list endpoint returning `[{...}]` with cryptor-response 
field encryption configured throws NPE → 500 on otherwise-valid responses.
   
   ## Suggested fix
   In `JsonUtil.parser`, null-check `map` after `toObjectMap` and return `null` 
early when the body is not a JSON object; in the dotted branch, null-check each 
`getAsJsonObject(...)` intermediate and return `null` (let the caller's 
`fieldErrorParse` handle it) instead of dereferencing.
   
   ## Related existing
   None — distinct from GW-MOD-3 (#6635, the shared-mutable-depth bug in 
`replaceJsonNode` at lines 93-131, a different method).
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to