jackson-databind: catch false positive (#8308)

Signed-off-by: AdamKorcz <adam@adalogics.com>

Signed-off-by: AdamKorcz <adam@adalogics.com>
This commit is contained in:
AdamKorcz 2022-08-22 15:36:11 +01:00 committed by GitHub
parent f6c3e1862b
commit c3d8ca5b8e
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
1 changed files with 7 additions and 2 deletions

View File

@ -28,6 +28,7 @@ import java.util.Arrays;
import java.lang.NoSuchMethodException;
import java.lang.IllegalAccessException;
import java.lang.ClassNotFoundException;
import java.lang.ArrayIndexOutOfBoundsException;
import java.lang.reflect.*;
import java.lang.reflect.Method;
import java.net.URL;
@ -52,8 +53,12 @@ public class ObjectReaderRandomClassFuzzer {
String classString = data.consumeString(1000000);
// Sanity check: Do we have valid java code? If not, exit early.
List<Problem> problems = Roaster.validateSnippet(classString);
if (problems.size()>0) {
try {
List<Problem> problems = Roaster.validateSnippet(classString);
if (problems.size()>0) {
return;
}
} catch (ArrayIndexOutOfBoundsException e) {
return;
}