Skip to content

Comments

add guardrails for deserialization#371

Open
htanwar-atlassian wants to merge 5 commits intox-stream:v-1.4.xfrom
atlassian-forks:CONFSRVDEV-370870-add-guardrails-for-deserialization
Open

add guardrails for deserialization#371
htanwar-atlassian wants to merge 5 commits intox-stream:v-1.4.xfrom
atlassian-forks:CONFSRVDEV-370870-add-guardrails-for-deserialization

Conversation

@htanwar-atlassian
Copy link

Added checks for xml depth, field count, and field size when deserializing. The limits are configurable by the user.
Adding these limits helps in reducing DoS attacks and having stackoverflow exceptions.

The code for adding getLevel is taken from
dfa1d35#diff-eb24140ebbc07aeaa89319c00c32d44fe0f7ee38d8e769039935c60fa5351a5a

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant