Introduce black list for classloading

Issue #564 wontfix
Andrey Somov created an issue

Comments (10)

  1. Anton Pryamostanov

    Hi Andrey, Can you please share some details, what is the issue and in which library. So it could be tracked accordingly with them. Currently CVE points here and there is no detail.

    Thank you.

  2. Andrey Somov reporter

    @Anton Pryamostanov I did not quite catch you.
    This particular issue was an attempt to introduce a blacklist. It was rejected.

    Which CVE points here ?

  3. Anton Pryamostanov

    Hi Andrey, understood. Thank you for clarifying. It was same CVE (CVE-2022-1471), I will use solution from #561 (Snake YAML 2.0).

  4. Andrey Somov reporter

    When you use Spring there is no issue and the report is a false positive. Either ignore it or file bug in checkmars

  5. Log in to comment