SEZ9 commented on PR #11559: URL: https://github.com/apache/seatunnel/pull/11559#issuecomment-5650851616
On PR11559-F1 (unsafe Java deserialization pattern in `seatunnel-connectors-v2/connector-kafka/src/main/java/org/apache/seatunnel/connectors/seatunnel/kafka/source/KafkaSourceReader.java`): I can't mark this resolved yet. The two new commits, `779004c073` and `4d75844b4a`, are described as the config path-separator fix and the merge of current `dev`, and neither is described as changing `KafkaSourceReader.java`. I also don't have diff evidence in front of me showing how deserialization is restricted in that file at `4d75844b4af1e1f906594ba32a0e0ac4ff4ecbe7`. Could you point me to the specific commit and lines in `KafkaSourceReader.java` where the fix lives (for example, a `resolveClass` allowlist)? Once I can confirm it against the actual diff, I'll close this finding out. Thanks! <!-- streview-comment:1014 --> -- This is an automated message from the Apache Git Service. To respond to the message, please log on to GitHub and use the URL above to go to the specific comment. To unsubscribe, e-mail: [email protected] For queries about this service, please contact Infrastructure at: [email protected]
