ppkarwasz opened a new pull request, #4271:
URL: https://github.com/apache/logging-log4j2/pull/4271

   > [!IMPORTANT]
   > This PR is part of the deserialization hardening work tracked in #4168. 
The Logging Services PMC does **not** use nor recommend Java 
serialization/deserialization, and [our security 
FAQ](https://logging.apache.org/security/faq.html#deserialization) has long 
documented this position. This work is submitted solely to reduce the 
false-positive "vulnerability" reports that keep being filed regardless of that 
FAQ. Its utility for end users is close to zero.
   
   Since 2.8.2, `Log4jLogEvent.LogEventProxy` transported its `Message` 
delegate inside a `java.rmi.MarshalledObject`. `MarshalledObject.get()` 
deserializes its embedded bytes on a private, unfiltered `ObjectInputStream`, 
so the nested message bypassed both `FilteredObjectInputStream` and the JEP 290 
filter.
   
   The message is now written with the same 
`SerializationUtil.writeWrappedObject`/`readWrappedObject` mechanism already 
used by `ObjectMessage`, which re-applies the deserialization filter to the 
nested stream, and `java.rmi.MarshalledObject` is removed from the allowlist. A 
message that is rejected or unreadable on the receiving side degrades to a 
`SimpleMessage` built from the formatted message string, as before.
   
   **Compatibility:** this changes the serialized form of `LogEventProxy`.
   - Log events serialized by Log4j 2.8.2–2.25.x are **rejected** by readers 
with this change, since `MarshalledObject` no longer passes the filter.
   - Events serialized with this change remain readable by older versions, with 
the message downgraded to a `SimpleMessage`.
   - Previously, a message that threw during serialization was silently 
replaced by its formatted string on the **writing** side; matching 
`ObjectMessage` semantics, such a failure now propagates to the caller as an 
`IOException`.
   
   The serialized-event fixture in `Log4jLogEventTest` predated 
`nanoOfMillisecond` and the trace-context fields and has been regenerated; the 
stale `serializedEvent.dat` test resource was unused (`SerializedLayoutTest` 
always rewrites it before reading) and is removed.
   
   Stacked on #4270.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to