Prev Next

Web / Apache Commons Collections Interview questions

Why is Apache Commons Collections associated with a well-known deserialization vulnerability?

In 2015, security researchers demonstrated that several of the library's reflective functor classes could be chained together to build a so-called "gadget chain" - a sequence of ordinary, individually harmless objects that, when deserialized in a specific combination, ends up executing arbitrary code.

// simplified concept: chaining transformers so deserializing
// a TransformedMap/LazyMap triggers a reflective method call
Transformer chain = ChainedTransformer(
    ConstantTransformer(Runtime.class),
    InvokerTransformer("getMethod", ...),
    InvokerTransformer("invoke", ...)
);

The core piece enabling this was InvokerTransformer, which reflectively invokes a named method on whatever object it's given; combined with ChainedTransformer to sequence several calls, and a TransformedMap or LazyMap whose transform runs automatically during deserialization, an attacker could trigger a chain ending in something like Runtime.exec() purely by having a vulnerable application deserialize a malicious object stream.

The underlying root cause was Java's own default object deserialization trusting the incoming object graph without restriction - Commons Collections wasn't uniquely broken, but its powerful reflective functor classes happened to provide one of the easiest, most widely available gadget chains for exploiting that broader Java weakness. In response, later releases made InvokerTransformer and similar classes non-serializable by default, requiring an explicit opt-in system property to restore the old (riskier) behavior.

The functor class most central to the gadget chain was:
The underlying root cause of the vulnerability class was:

More Related questions...

What is Apache Commons Collections? What are the main packages in Apache Commons Collections 4? What is a Bag in Apache Commons Collections? What are the types of Bag implementations in Commons Collections? What is a BidiMap in Apache Commons Collections? What is a MultiValuedMap in Apache Commons Collections? What is the purpose of CollectionUtils in Apache Commons Collections? What is the purpose of MapUtils in Apache Commons Collections? What is the purpose of ListUtils in Apache Commons Collections? What are Predicates in Apache Commons Collections? What are Transformers in Apache Commons Collections? What are Closures in Apache Commons Collections? What is a Factory in Apache Commons Collections? Define CircularFifoQueue in Apache Commons Collections? What is an LRUMap in Apache Commons Collections? What is a ReferenceMap in Apache Commons Collections? What is a MultiKeyMap in Apache Commons Collections? What is the purpose of IteratorUtils in Apache Commons Collections? Describe the LoopingIterator class in Apache Commons Collections? What is an OrderedMap in Apache Commons Collections? What is a SortedBidiMap in Apache Commons Collections? What is the purpose of ComparatorUtils in Apache Commons Collections? Define FixedOrderComparator in Apache Commons Collections? What is a PredicatedCollection in Apache Commons Collections? What is a TransformedCollection in Apache Commons Collections? What is the difference between a Map and a MultiValuedMap? What is the difference between a BidiMap and a regular Map? Why is CollectionUtils.isEmpty() preferred over calling isEmpty() directly? How does a TreeBag maintain element ordering internally? How does LRUMap decide which entry to evict? What is the difference between HashBag and TreeBag? Why do we use predicate chaining with allPredicate and anyPredicate? How is UnmodifiableMap in Commons Collections different from java.util's Collections.unmodifiableMap? What happens when you add a duplicate value to a BidiMap? How does PredicatedList enforce validation on add operations? Explain the internal working of CircularFifoQueue? How can you optimize repeated multi-field lookups using MultiKeyMap? What is the difference between Apache Commons Collections 3.x and 4.x? Why should you use TransformedMap instead of manual validation in setters? When should you choose Apache Commons Collections over Guava collections? Explain the execution flow of CollectionUtils.collect()? How is FactoryUtils used to lazily create objects? Why is Apache Commons Collections associated with a well-known deserialization vulnerability? What is the difference between the legacy MultiMap (3.x) and MultiValuedMap (4.x)? How does ReferenceMap help prevent memory leaks in long-running caches? Why doesn't a Bag simply behave like a Set? How do you troubleshoot a ConcurrentModificationException when using CollectionUtils.filter()? Explain the lifecycle of a ClosureUtils.chainedClosure() execution? What is the difference between SetUtils.union() and manually merging two sets? How does Commons Collections' Trie support prefix-based lookups?
Show more question and Answers...


Comments & Discussions