[
https://issues.apache.org/jira/browse/WW-5644?focusedWorklogId=1030773&page=com.atlassian.jira.plugin.system.issuetabpanels:worklog-tabpanel#worklog-1030773
]
ASF GitHub Bot logged work on WW-5644:
--------------------------------------
Author: ASF GitHub Bot
Created on: 16/Jul/26 13:49
Start Date: 16/Jul/26 13:49
Worklog Time Spent: 10m
Work Description: lukaszlenart commented on PR #1776:
URL: https://github.com/apache/struts/pull/1776#issuecomment-4992672324
Please follow the responsible disclosure process and ask such questions via
[[email protected]](mailto:[email protected]) as documented
in the
[SECURITY.md](https://github.com/apache/struts/blob/main/SECURITY.md#do-not-disclose-through-a-pull-request-commit-or-issue)
Issue Time Tracking
-------------------
Worklog Id: (was: 1030773)
Time Spent: 1h 20m (was: 1h 10m)
> StrutsJSONWriter write state shared across concurrent requests cross-request
> response leakage
> ----------------------------------------------------------------------------------------------
>
> Key: WW-5644
> URL: https://issues.apache.org/jira/browse/WW-5644
> Project: Struts 2
> Issue Type: Bug
> Components: Plugin - JSON
> Affects Versions: 7.2.1
> Environment: Reproducible under concurrent response serialization via
> the default
> "json" result type or JSONInterceptor, no special configuration
> required. JDK 17, Jackson 2.22.0, any Servlet container. Confirmed via
> a 16-thread contention test against a single shared StrutsJSONWriter
> instance (44,646/320,000 corrupted responses observed pre-fix).
> Reporter: Gouri Sankar A
> Priority: Major
> Fix For: 7.3.0
>
> Time Spent: 1h 20m
> Remaining Estimate: 0h
>
> JSONUtil's JSONWriter is injected once and reused across every
> concurrent response handled by that JSONResult/JSONInterceptor.
> StrutsJSONWriter kept its output buffer and other per-write state as
> plain instance fields, reset in place at the start of write(). Two
> concurrent write() calls race on that reset: one call's in-progress
> buffer can be wiped and overwritten by a second call before the first
> reads it back, so one request's serialized JSON can be returned as a
> completely different, concurrently-served request's response body —
> exercised by the default json result type on every request.
> Fix: move per-write state into a ThreadLocal-confined object, scoped to
> a single write() call.
> Fixed by: https://github.com/apache/struts/pull/1776
--
This message was sent by Atlassian Jira
(v8.20.10#820010)