如何禁用Jackson DefaultTyping?确认默认状态及关闭多态行为
Great question—let’s walk through this step by step since locking down Jackson against polymorphic deserialization vulnerabilities is super important, especially when you don’t need any polymorphic behavior at all.
First: Jackson 2.10.0 Default Behavior (Critical to Know)
First off, let’s clear up your biggest concern: DefaultTyping is NOT enabled by default in Jackson 2.10.0. Whether you’re using ObjectMapper (JSON), XmlMapper (XML), or CsvMapper (CSV), none of these will automatically process polymorphic type markers like @type to instantiate subclass types out of the box. So if you haven’t explicitly enabled this feature, your setup is already not using polymorphic deserialization.
Do NOT Call activateDefaultTyping()—It’s the Opposite of What You Want
You mentioned wondering if you need to call activateDefaultTyping() and use a PolymorphicTypeValidator to shut things down: don’t do this. The activateDefaultTyping() method is explicitly for enabling polymorphic type handling, not disabling it. Since you don’t need any polymorphic behavior, you shouldn’t touch this method at all.
How to Fully Block All Polymorphic Behavior (Even If Someone Tries to Enable It)
To make absolutely sure no polymorphic deserialization can happen—even if a teammate accidentally enables it later or a library dependency tries to override settings—use these configurations tailored to your Spring Boot 2.1.9 setup:
1. Spring Boot Configuration (JSON, XML, CSV)
For JSON (Default Jackson Setup)
Add these properties to your application.properties or application.yml to enforce secure defaults:
# Disable default typing entirely spring.jackson.mapper.default-typing=DISABLED # Reject unknown properties (blocks malicious fields like @type if someone sends them) spring.jackson.deserialization.fail-on-unknown-properties=true
For XML (Using jackson-dataformat-xml)
If you’re working with XML, create a custom configuration bean to lock down XmlMapper:
@Configuration public class JacksonXmlSecurityConfig { @Bean public XmlMapper xmlMapper() { XmlMapper xmlMapper = new XmlMapper(); // Core: Turn off all polymorphic type handling xmlMapper.disable(MapperFeature.USE_DEFAULT_TYPING); // Reject any unknown properties to block malicious input xmlMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES); return xmlMapper; } }
For CSV (Using jackson-dataformat-csv)
Similarly, configure CsvMapper explicitly to disable typing:
@Configuration public class JacksonCsvSecurityConfig { @Bean public CsvMapper csvMapper() { CsvMapper csvMapper = new CsvMapper(); csvMapper.disable(MapperFeature.USE_DEFAULT_TYPING); csvMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES); return csvMapper; } }
2. Raw Jackson (Non-Spring Boot)
If you’re using Jackson directly outside Spring Boot’s auto-configuration, apply the same flags directly to your mapper instances:
// JSON ObjectMapper jsonMapper = new ObjectMapper(); jsonMapper.disable(MapperFeature.USE_DEFAULT_TYPING); jsonMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES); // XML XmlMapper xmlMapper = new XmlMapper(); xmlMapper.disable(MapperFeature.USE_DEFAULT_TYPING); xmlMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES); // CSV CsvMapper csvMapper = new CsvMapper(); csvMapper.disable(MapperFeature.USE_DEFAULT_TYPING); csvMapper.enable(DeserializationFeature.FAIL_ON_UNKNOWN_PROPERTIES);
Why This Configuration Is Rational for Your Use Case
Since you explicitly don’t need polymorphic behavior:
- Disabling
USE_DEFAULT_TYPINGeliminates the entire attack surface for polymorphic deserialization vulnerabilities (like remote code execution via malicious@typevalues). - Enabling
FAIL_ON_UNKNOWN_PROPERTIESadds an extra layer of defense: if an attacker tries to send a@typefield (or any other unrecognized property), the deserialization will fail immediately. - This setup doesn’t interfere with normal serialization/deserialization of your non-polymorphic classes—you’ll still get all the core Jackson functionality you need without the risk.
Final Recap
- Your current default setup (Jackson 2.10.0 + Spring Boot 2.1.9) doesn’t have DefaultTyping enabled—no immediate risk there.
- Never call
activateDefaultTyping()unless you specifically need polymorphic behavior (which you don’t). - Use
disable(MapperFeature.USE_DEFAULT_TYPING)to permanently block all polymorphic type handling. - Pair it with
FAIL_ON_UNKNOWN_PROPERTIES=trueto harden against malicious input.
内容的提问来源于stack exchange,提问作者Stuart

