[ https://issues.apache.org/jira/browse/LUCENE-9094?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ]
Robert Muir resolved LUCENE-9094. --------------------------------- Resolution: Fixed > Ban ObjectInputStream and ObjectOutputStream in forbidden-apis > -------------------------------------------------------------- > > Key: LUCENE-9094 > URL: https://issues.apache.org/jira/browse/LUCENE-9094 > Project: Lucene - Core > Issue Type: Task > Components: general/build > Reporter: Robert Muir > Assignee: Robert Muir > Priority: Major > Fix For: 8.5 > > Attachments: LUCENE-9094.patch > > > suggested build failure message: > {quote} > [forbidden-apis] Forbidden class/interface use: java.io.ObjectInputStream > [Java deserialization is unsafe when the data is untrusted. The java > developer is powerless: no checks or casts help, exploitation can happen in > places such as clinit or finalize!] > {quote} > I will whitelist existing places doing this for now. -- This message was sent by Atlassian Jira (v8.3.4#803005) --------------------------------------------------------------------- To unsubscribe, e-mail: issues-unsubscr...@lucene.apache.org For additional commands, e-mail: issues-h...@lucene.apache.org