Skip to content

Commit 61488d4

Browse files
committed
Added two more known vulnerable classes suggested by Mo.
1 parent 489f564 commit 61488d4

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

src/main/java/org/apache/ibatis/executor/loader/AbstractSerialStateHolder.java

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -133,12 +133,15 @@ protected abstract Object createDeserializationProxy(Object target, Map<String,
133133

134134
private static class LookAheadObjectInputStream extends ObjectInputStream {
135135
private static final List<String> blacklist = Arrays.asList(
136+
"org.apache.commons.beanutils.BeanComparator",
136137
"org.apache.commons.collections.functors.InvokerTransformer",
137138
"org.apache.commons.collections.functors.InstantiateTransformer",
138139
"org.apache.commons.collections4.functors.InvokerTransformer",
139140
"org.apache.commons.collections4.functors.InstantiateTransformer",
140-
"org.codehaus.groovy.runtime.ConvertedClosure", "org.codehaus.groovy.runtime.MethodClosure",
141+
"org.codehaus.groovy.runtime.ConvertedClosure",
142+
"org.codehaus.groovy.runtime.MethodClosure",
141143
"org.springframework.beans.factory.ObjectFactory",
144+
"org.springframework.transaction.jta.JtaTransactionManager",
142145
"com.sun.org.apache.xalan.internal.xsltc.trax.TemplatesImpl");
143146

144147
public LookAheadObjectInputStream(InputStream in) throws IOException {

0 commit comments

Comments
 (0)