You are viewing a plain text version of this content. The canonical link for it is here.
Posted to notifications@james.apache.org by "chibenwa (via GitHub)" <gi...@apache.org> on 2023/02/22 04:53:34 UTC

[GitHub] [james-project] chibenwa opened a new pull request, #1457: JAMES-3881 Prevent CommonsBeanutils1 deserialization exploit

chibenwa opened a new pull request, #1457:
URL: https://github.com/apache/james-project/pull/1457

   CF https://github.com/frohoff/ysoserial
   
   This was possible through the commons-logging 1.2 transitive dependency.


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org
For additional commands, e-mail: notifications-help@james.apache.org


[GitHub] [james-project] chibenwa merged pull request #1457: JAMES-3881 Prevent CommonsBeanutils1 deserialization exploit

Posted by "chibenwa (via GitHub)" <gi...@apache.org>.
chibenwa merged PR #1457:
URL: https://github.com/apache/james-project/pull/1457


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org
For additional commands, e-mail: notifications-help@james.apache.org


[GitHub] [james-project] Arsnael commented on pull request #1457: JAMES-3881 Prevent CommonsBeanutils1 deserialization exploit

Posted by "Arsnael (via GitHub)" <gi...@apache.org>.
Arsnael commented on PR #1457:
URL: https://github.com/apache/james-project/pull/1457#issuecomment-1439534568

   here starts the long dependency battle with maven: https://ci-builds.apache.org/job/james/job/ApacheJames/job/PR-1457/1/testReport/
   
   Good luck :)


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org

For queries about this service, please contact Infrastructure at:
users@infra.apache.org


---------------------------------------------------------------------
To unsubscribe, e-mail: notifications-unsubscribe@james.apache.org
For additional commands, e-mail: notifications-help@james.apache.org