ramanathan1504 commented on PR #4274:
URL: https://github.com/apache/logging-log4j2/pull/4274#issuecomment-5574087325
`ParameterizedMessage` is byte for byte the same, I checked.
`ObjectArrayMessage` also degrades a non-serializable element now instead of
throwing.
But the reason for rejecting the single blob applies here too. Each
element wrapper is a `byte[]` read by `in.readObject()` on the outer stream, at
a length the JDK trusts. I
patched that length in a 103 byte `ObjectMessage` from 12 to 400 million
and both filter paths give `OutOfMemoryError` under `-Xmx64m`. Can we bound
`filterInfo.arrayLength()` in `DefaultObjectInputFilter` instead?
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]