infinispan/CVE-2017-15089-2.patch
zhanghua1831 f4489b85a0 fix CVE-2016-0750 CVE-2017-15089
(cherry picked from commit f8ecc5c42f4db067372d425facf2f4eb4b308959)
2021-03-05 15:02:17 +08:00

26 lines
1.5 KiB
Diff

From 57ddebc99ed35a4531ce4d8821090faed24e7eaf Mon Sep 17 00:00:00 2001
From: =?UTF-8?q?Galder=20Zamarren=CC=83o?= <galder@zamarreno.com>
Date: Wed, 13 Dec 2017 11:44:14 +0100
Subject: [PATCH] ISPN-8624 Custom marshaller implementors should verify class
names
* Add documentation entry to make sure any custom marshaller
implementations implement white class name verification.
---
.../infinispan/it/compatibility/CompatibilityCacheFactory.java | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/integrationtests/compatibility-mode-it/src/test/java/org/infinispan/it/compatibility/CompatibilityCacheFactory.java b/integrationtests/compatibility-mode-it/src/test/java/org/infinispan/it/compatibility/CompatibilityCacheFactory.java
index a648816d053..c0b5351b761 100644
--- a/integrationtests/compatibility-mode-it/src/test/java/org/infinispan/it/compatibility/CompatibilityCacheFactory.java
+++ b/integrationtests/compatibility-mode-it/src/test/java/org/infinispan/it/compatibility/CompatibilityCacheFactory.java
@@ -163,7 +163,7 @@ private void createHotRodCache(HotRodServer server) {
hotrod = server;
hotrodClient = new RemoteCacheManager(new ConfigurationBuilder()
.addServers("localhost:" + hotrod.getPort())
- .addJavaSerialWhiteList(".*Person.*")
+ .addJavaSerialWhiteList(".*Person.*", ".*CustomEvent.*")
.marshaller(marshaller)
.build());
hotrodCache = cacheName.isEmpty()