[ 
https://issues.apache.org/jira/browse/OFBIZ-11261?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=16960548#comment-16960548
 ] 

Jacques Le Roux commented on OFBIZ-11261:
-----------------------------------------

Thanks Mathieu,

Just curious, how did you find that bug? Did you had to add a class?

In your commit you say:
bq. The tests have not been backported from ‘trunk’ because of the way 
‘UtilProperties#setPropertyValueInMemory’ work in 18.12.

Because it's related to a security issue covered by OFBIZ-10837 we need bo 
backport the fix in all supported releases branches whatever it takes. 
I did it for
R17 r1869032
R16 r1869033

> UtilObject#getObjectException does not handle properties properly
> -----------------------------------------------------------------
>
>                 Key: OFBIZ-11261
>                 URL: https://issues.apache.org/jira/browse/OFBIZ-11261
>             Project: OFBiz
>          Issue Type: Bug
>          Components: framework
>    Affects Versions: Trunk
>            Reporter: Mathieu Lirzin
>            Assignee: Mathieu Lirzin
>            Priority: Major
>             Fix For: Upcoming Branch, Release Branch 18.12
>
>         Attachments: 
> OFBIZ-11261_0001-Improved-Write-tests-for-UtilObject-getObjectExcepti.patch, 
> OFBIZ-11261_0002-Fixed-Handle-whitelist-of-serializable-classes-from-.patch, 
> OFBIZ-11261_0003-Improved-Refactor-UtilObject-getObjectException.patch
>
>




--
This message was sent by Atlassian Jira
(v8.3.4#803005)

Reply via email to