@michael-o I understand what you mean. In fact, many old technologies or standards will often bring security problems if they are applied to practice without modification.Log4jshell is a good example. So even if the JNDI URL specification is like that, I think we should consider its impact in the actual environment, such as some functions that people don't often use, or some functions that attackers often use. Finally, like you, I'm interested in finding out the possible security problems in the code, and I'm just a happy user like you. ![]() |