Limit JSON Pointer path depth to 255 for $jsonSchema.encryptMetadata.keyId

XMLWordPrintableJSON

    • Type: Task
    • Resolution: Fixed
    • Priority: Major - P3
    • 8.2.13, 8.3.9, 7.0.41, 8.0.30, 9.0.0-rc2
    • Affects Version/s: None
    • Component/s: None
    • None
    • Query Integration
    • Fully Compatible
    • v9.0, v8.3, v8.2, v8.0, v7.0
    • None
    • None
    • None
    • None
    • None
    • None
    • None

      Fix for CVE-714. See issue summary in google doc: https://docs.google.com/document/d/1-fRGDJ0M4_f1uddJLlCro3BqP7VFBbxLayz-z1dacBg/edit?tab=t.0#heading=h.xgujahakvhno

      By limiting the path depth of the field in question for the CVE, we eliminate the possibility for making nonsensically / maliciously deep path that triggers the OOM, while not affecting any normal user functionality.

      There is existing precedent in the server for limiting the path length of a document to 255 (here)

            Assignee:
            Joe Shalabi
            Reporter:
            Joe Shalabi
            Votes:
            0 Vote for this issue
            Watchers:
            4 Start watching this issue

              Created:
              Updated:
              Resolved: