Skip to content

Commit 4c18b71

Browse files
authored
Merge pull request #1087 from weibocom/fix_security_issue
add serialize blacklist
2 parents b5f3c42 + a898304 commit 4c18b71

File tree

1 file changed

+4
-0
lines changed

1 file changed

+4
-0
lines changed

motan-core/src/main/java/com/weibo/api/motan/serialize/Hessian2Serialization.java

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -175,6 +175,10 @@ private static SerializerFactory initDefaultSerializerFactory() {
175175
classFactory.deny("sun.print.*");
176176
classFactory.deny("sun.rmi.*");
177177
classFactory.deny("sun.swing.*");
178+
classFactory.deny("com.alibaba.citrus.springext.*");
179+
classFactory.deny("com.alipay.custrelation.*");
180+
classFactory.deny("com.alibaba.druid.*");
181+
classFactory.deny("org.apache.catalina.tribes.*");
178182
} catch (Exception e) {
179183
LoggerUtil.warn("Hessian2Serialization init deny list failed, please upgrade hessian to version 4.0.66 or later", e);
180184
}

0 commit comments

Comments
 (0)