ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy
Assessment: Fully addressed.
When the serialised stream contains a TC_PROXYCLASSDESC (the marker for a java.lang.reflect.Proxy ), JDK’s ObjectInputStream.readProxyDesc() is dispatched. JDK then calls the default ObjectInputStream.resolveProxyClass(interfaces) implementation, which performs Class.forName(intf, false, latestUserDefinedLoader()) for EACH interface name and constructs the proxy class — bypassing the accepted classes list .
ZDRES-233: Class.forName(name, initialize=true, classLoader) in readClassDescriptor Triggers Static Initialiser of Allow-Listed Classes
Assessment: Fully addressed.
For ANY class on the allow-list, deserialising a stream that names it triggers the class’s (static initialiser) BEFORE any instance is constructed. This means an attacker who supplies a class name on the allow-list (e.g., the developer wrote accept(“com.myapp.*) , attacker supplies com.myapp.SomeClass ) causes of SomeClass — and many real-world classes have side-effecting static initialisers
Both issues have been fixed.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Mina | Apache | 2.0.29 (including) | 2.0.29 (including) |
| Mina | Apache | 2.1.13 (including) | 2.1.13 (including) |
| Mina | Apache | 2.2.8 (including) | 2.2.8 (including) |
| Mina2 | Ubuntu | devel | * |
| Mina2 | Ubuntu | esm-apps/jammy | * |
| Mina2 | Ubuntu | esm-apps/noble | * |
| Mina2 | Ubuntu | esm-apps/resolute | * |
| Mina2 | Ubuntu | jammy | * |
| Mina2 | Ubuntu | noble | * |
| Mina2 | Ubuntu | questing | * |
| Mina2 | Ubuntu | resolute | * |