ramanathan1504 commented on PR #4274:
URL: https://github.com/apache/logging-log4j2/pull/4274#issuecomment-5574087325

   `ParameterizedMessage` is byte for byte the same, I checked. 
`ObjectArrayMessage` also degrades a non-serializable element now instead of 
throwing.                           
                                                                                
                                                                                
                   
     But the reason for rejecting the single blob applies here too. Each 
element wrapper is a `byte[]` read by `in.readObject()` on the outer stream, at 
a length the JDK trusts. I
     patched that length in a 103 byte `ObjectMessage` from 12 to 400 million 
and both filter paths give `OutOfMemoryError` under `-Xmx64m`. Can we bound     
                     
     `filterInfo.arrayLength()` in `DefaultObjectInputFilter` instead?    


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to