SEZ9 commented on PR #11559:
URL: https://github.com/apache/seatunnel/pull/11559#issuecomment-5650851616

   On PR11559-F1 (unsafe Java deserialization pattern in 
`seatunnel-connectors-v2/connector-kafka/src/main/java/org/apache/seatunnel/connectors/seatunnel/kafka/source/KafkaSourceReader.java`):
 I can't mark this resolved yet. The two new commits, `779004c073` and 
`4d75844b4a`, are described as the config path-separator fix and the merge of 
current `dev`, and neither is described as changing `KafkaSourceReader.java`. I 
also don't have diff evidence in front of me showing how deserialization is 
restricted in that file at `4d75844b4af1e1f906594ba32a0e0ac4ff4ecbe7`.
   
   Could you point me to the specific commit and lines in 
`KafkaSourceReader.java` where the fix lives (for example, a `resolveClass` 
allowlist)? Once I can confirm it against the actual diff, I'll close this 
finding out. Thanks!
   
   <!-- streview-comment:1014 -->


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to