ramanathan1504 commented on code in PR #4269:
URL: https://github.com/apache/logging-log4j2/pull/4269#discussion_r3951337223


##########
log4j-api/src/main/java/org/apache/logging/log4j/util/FilteredObjectInputStream.java:
##########
@@ -71,6 +71,20 @@ protected Class<?> resolveClass(final ObjectStreamClass 
desc) throws IOException
         return super.resolveClass(desc);
     }
 
+    /**
+     * Unconditionally rejects dynamic proxy classes.
+     * <p>
+     *     Proxy class descriptors do not pass through {@link 
#resolveClass(ObjectStreamClass)}, so they would
+     *     otherwise bypass the allowlist entirely. No supported Log4j 
serialized form contains a dynamic proxy, and
+     *     the JEP 290 filter used on Java 9 and later rejects proxy classes 
as well, since their synthetic class names
+     *     never match the allowlist.

Review Comment:
   This is true only with the default filter. 
`DefaultObjectInputFilter.checkInput` asks the process-wide `jdk.serialFilter` 
first and returns its answer. So a permissive one still lets a proxy through on 
Java 9+.
   
   ```suggestion
        *     {@code DefaultObjectInputFilter} rejects proxy classes on Java 9 
and later, since their synthetic class
        *     names never match the allowlist, unless a process-wide serial 
filter allows them first.
   ```



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to