[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2017-04-25 Thread Trejkaz (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15983941#comment-15983941 ] Trejkaz commented on AMQ-6013: -- The commit to fix this makes serializablePackages a public mutable array:

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-08 Thread Imran Ali (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15046701#comment-15046701 ] Imran Ali commented on AMQ-6013: Based on [~mbechler] comment: Can you please confirm if this fix is also

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-08 Thread Moritz Bechler (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15046732#comment-15046732 ] Moritz Bechler commented on AMQ-6013: - Yes, that's correct. There has been some discussion about how to

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-08 Thread Dejan Bosanac (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15046712#comment-15046712 ] Dejan Bosanac commented on AMQ-6013: Hi Imran, yes it's the same root of the issue. I'm working on

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-08 Thread Dejan Bosanac (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15047070#comment-15047070 ] Dejan Bosanac commented on AMQ-6013: This issue is related to CVE-2015-5254 as described at

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-07 Thread Brett E. Meyer (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15045216#comment-15045216 ] Brett E. Meyer commented on AMQ-6013: - Fair enough on the reasoning -- makes sense. However, I'd

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-05 Thread Moritz Bechler (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15043298#comment-15043298 ] Moritz Bechler commented on AMQ-6013: - Btw, you might want to have a look at your own

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-03 Thread Brett E. Meyer (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15040437#comment-15040437 ] Brett E. Meyer commented on AMQ-6013: - Is there any explanation available for why this change was made?

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-03 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15038279#comment-15038279 ] ASF subversion and git services commented on AMQ-6013: -- Commit

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-12-03 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15038278#comment-15038278 ] ASF subversion and git services commented on AMQ-6013: -- Commit

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-11-16 Thread Dejan Bosanac (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15006631#comment-15006631 ] Dejan Bosanac commented on AMQ-6013: Hi David, I looked at this some more and I don't think we have a

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-11-13 Thread David Jencks (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004213#comment-15004213 ] David Jencks commented on AMQ-6013: --- I'd expect you'd want to check if the class is allowed based on its

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-10-28 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14978443#comment-14978443 ] ASF subversion and git services commented on AMQ-6013: -- Commit

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-10-28 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14978442#comment-14978442 ] ASF subversion and git services commented on AMQ-6013: -- Commit

[jira] [Commented] (AMQ-6013) Restrict classes that can be serialized in ObjectMessages

2015-10-20 Thread ASF subversion and git services (JIRA)
[ https://issues.apache.org/jira/browse/AMQ-6013?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=14964943#comment-14964943 ] ASF subversion and git services commented on AMQ-6013: -- Commit