[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003912#comment-15003912 ] Karsten Klein commented on COLLECTIONS-580: --- We (not having seen the attached patch before)

[jira] [Comment Edited] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003912#comment-15003912 ] Karsten Klein edited comment on COLLECTIONS-580 at 11/13/15 12:16 PM:

[jira] [Comment Edited] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003912#comment-15003912 ] Karsten Klein edited comment on COLLECTIONS-580 at 11/13/15 12:19 PM:

[jira] [Comment Edited] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003912#comment-15003912 ] Karsten Klein edited comment on COLLECTIONS-580 at 11/13/15 12:20 PM:

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004571#comment-15004571 ] Adrian Crum commented on IO-487: Gary - right now I think we are trying to settle on an API. If there is

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004397#comment-15004397 ] Bertrand Delacretaz commented on IO-487: Forgot to mention good contributions from

[jira] [Created] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
Bertrand Delacretaz created IO-487: -- Summary: SafeObjectInputStream contribution - restrict which classes can be deserialized Key: IO-487 URL: https://issues.apache.org/jira/browse/IO-487 Project:

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Gary Gregory (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004566#comment-15004566 ] Gary Gregory commented on IO-487: - Is someone wiling to look at code coverage reports with Jacoco and/or

[jira] [Updated] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Bertrand Delacretaz updated IO-487: --- Attachment: IO-487.patch > SafeObjectInputStream contribution - restrict which classes can be >

[jira] [Updated] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Adrian Crum updated IO-487: --- Attachment: IO-487.patch Improved patch attached. Added missing @Overrides, added missing JavaDocs, added more

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Gary Gregory (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004583#comment-15004583 ] Gary Gregory commented on IO-487: - Ah, OK, thank you for the update. Since are still kibitzing, then I'd like

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004415#comment-15004415 ] Adrian Crum commented on IO-487: Some suggestions: 1. Use UnsupportedOperationException instead of custom

[jira] [Updated] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Bertrand Delacretaz updated IO-487: --- Attachment: IO-487.patch Here's an updated patch that uses UnsupportedOperationException, good

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004563#comment-15004563 ] Bertrand Delacretaz commented on IO-487: You are welcome! > SafeObjectInputStream contribution -

[jira] [Updated] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Bertrand Delacretaz updated IO-487: --- Attachment: IO-487.patch Another update...just a comment change. > SafeObjectInputStream

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004453#comment-15004453 ] Adrian Crum commented on IO-487: If you don't mind, I would like to make a few improvements to your patch. >

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004657#comment-15004657 ] Adrian Crum commented on IO-487: Agreed. > SafeObjectInputStream contribution - restrict which classes can be

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004788#comment-15004788 ] Adrian Crum commented on IO-487: I just noticed my patch utility is creating duplicates within the patch. Let

[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Thomas Neidhart (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004712#comment-15004712 ] Thomas Neidhart commented on COLLECTIONS-580: - The new MultiValuedMap in collections4

[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Thomas Neidhart (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004640#comment-15004640 ] Thomas Neidhart commented on COLLECTIONS-580: - Committed in r1714262 for collections4:

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Christopher Schultz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004750#comment-15004750 ] Christopher Schultz commented on IO-487: I'm no expert in "commons land", but would this class be

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Gary Gregory (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004777#comment-15004777 ] Gary Gregory commented on IO-487: - This is clearly an IO class. > SafeObjectInputStream contribution -

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Christopher Schultz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004623#comment-15004623 ] Christopher Schultz commented on IO-487: RegexpClassAcceptor could be simpler by reducing the

[jira] [Updated] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Adrian Crum (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Adrian Crum updated IO-487: --- Attachment: IO-487.patch Updated patch that includes the suggestions made so far. I think the latest API is

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004870#comment-15004870 ] Bertrand Delacretaz commented on IO-487: RestrictedObjectInputStream? > SafeObjectInputStream

[jira] [Commented] (IO-487) SafeObjectInputStream contribution - restrict which classes can be deserialized

2015-11-13 Thread Bertrand Delacretaz (JIRA)
[ https://issues.apache.org/jira/browse/IO-487?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15004869#comment-15004869 ] Bertrand Delacretaz commented on IO-487: RestrictedObjectInputStream? > SafeObjectInputStream

[jira] [Commented] (SANDBOX-501) Add configurable type conversion support

2015-11-13 Thread Matthew P Mann (JIRA)
[ https://issues.apache.org/jira/browse/SANDBOX-501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15005133#comment-15005133 ] Matthew P Mann commented on SANDBOX-501: Some more tinkering today. Attaching a new patch. > Add

[jira] [Comment Edited] (SANDBOX-501) Add configurable type conversion support

2015-11-13 Thread Matthew P Mann (JIRA)
[ https://issues.apache.org/jira/browse/SANDBOX-501?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15005133#comment-15005133 ] Matthew P Mann edited comment on SANDBOX-501 at 11/14/15 3:34 AM: -- Some

[jira] [Updated] (SANDBOX-501) Add configurable type conversion support

2015-11-13 Thread Matthew P Mann (JIRA)
[ https://issues.apache.org/jira/browse/SANDBOX-501?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel ] Matthew P Mann updated SANDBOX-501: --- Attachment: commons-beanutils2.2015-11-13.patch > Add configurable type conversion support >

[jira] [Created] (IMAGING-175) Check download release

2015-11-13 Thread Thomas Hartwig (JIRA)
Thomas Hartwig created IMAGING-175: -- Summary: Check download release Key: IMAGING-175 URL: https://issues.apache.org/jira/browse/IMAGING-175 Project: Commons Imaging Issue Type: Bug

[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Thomas Neidhart (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003922#comment-15003922 ] Thomas Neidhart commented on COLLECTIONS-580: - I prefer a fail-fast approach. btw. a

[jira] [Comment Edited] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003932#comment-15003932 ] Karsten Klein edited comment on COLLECTIONS-580 at 11/13/15 12:37 PM:

[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Thomas Neidhart (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003970#comment-15003970 ] Thomas Neidhart commented on COLLECTIONS-580: - {quote} Not sure I fully understand. The

[jira] [Commented] (COLLECTIONS-580) Arbitrary remote code execution with InvokerTransformer

2015-11-13 Thread Karsten Klein (JIRA)
[ https://issues.apache.org/jira/browse/COLLECTIONS-580?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel=15003932#comment-15003932 ] Karsten Klein commented on COLLECTIONS-580: --- Not sure I fully understand. The critical