Skip to content

Commit 39f8353

Browse files
dougqhdatadog-datadog-prod-us1[bot]devflow.devflow-routing-intake
authored
Add ObjectInputStream.readObject to forbidden apis (#10952)
Add ObjectInputStream.readObject to forbidden apis Co-authored-by: dougqh <dougqh@gmail.com> Removing unnecessary defaultmessage added by AI Adding URL to relevant documentation Merge branch 'master' into dd/prevent-objectinputstream-deserialization Co-authored-by: datadog-datadog-prod-us1[bot] <88084959+datadog-datadog-prod-us1[bot]@users.noreply.github.com> Co-authored-by: devflow.devflow-routing-intake <devflow.devflow-routing-intake@kubernetes.us1.ddbuild.io>
1 parent 0ee26e8 commit 39f8353

File tree

1 file changed

+3
-0
lines changed

1 file changed

+3
-0
lines changed

gradle/forbiddenApiFilters/main.txt

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -50,3 +50,6 @@ java.lang.reflect.Field#setLong(java.lang.Object,long)
5050
java.lang.reflect.Field#setFloat(java.lang.Object,float)
5151
java.lang.reflect.Field#setDouble(java.lang.Object,double)
5252
java.lang.invoke.MethodHandles.Lookup#unreflectSetter(java.lang.reflect.Field)
53+
54+
# avoid Java deserialization entrypoint - see warning in https://docs.oracle.com/en/java/javase/25/docs/api/java.base/java/io/ObjectInputStream.html
55+
java.io.ObjectInputStream#readObject()

0 commit comments

Comments
 (0)