Summary
The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an ObjectInputFilter meant to allow only AuthenticatorImpl, but it short-circuits to ALLOWED for any object at stream depth > 1. Because the Java serialization filter is consulted for every class in the graph (and depth == 1 only for the root's concrete class), the allowlist constrains only the root and leaves the entire nested graph unchecked.
Impact
An attacker can craft a stream rooted at AuthenticatorImpl with an arbitrary gadget chain nested inside. The gadget's readObject/readResolve executes during readObject() — before the cast and before any assertion verification — enabling remote code execution when a gadget is on the classpath. The deserialization sink is reached pre-authentication via an attacker-chosen userHandle.
References
Summary
The GHSA-6c99-87fr-6q7r fix wrapped WebAuthn authenticator deserialization in an
ObjectInputFiltermeant to allow onlyAuthenticatorImpl, but it short-circuits toALLOWEDfor any object at streamdepth > 1. Because the Java serialization filter is consulted for every class in the graph (anddepth == 1only for the root's concrete class), the allowlist constrains only the root and leaves the entire nested graph unchecked.Impact
An attacker can craft a stream rooted at
AuthenticatorImplwith an arbitrary gadget chain nested inside. The gadget'sreadObject/readResolveexecutes duringreadObject()— before the cast and before any assertion verification — enabling remote code execution when a gadget is on the classpath. The deserialization sink is reached pre-authentication via an attacker-chosenuserHandle.References