Re: OSGi and ObjectInputStream.readObject() deserialization classloading

2016-11-03 Thread David Jencks
I think I’m repeating what Christian said…. Deseriailizing arbitrary classes usually results in a giant security exposure, as there are exploits that result in arbitrary code execution on deserialization (not use!) of some commonly used library class instances. Most of the projects I’m

webconsole and log service

2016-11-03 Thread Benson Margulies
I have the osgi-over-slf4j log service in place, but the web console tells me I have no log service. What is the web console looking for? - To unsubscribe, e-mail: users-unsubscr...@felix.apache.org For additional commands,