Skip to content

Prohibit deserialization of Object fields by default #26914

@daniel-beck

Description

@daniel-beck

What feature do you want to see added?

SECURITY-3707 demonstrates the risk involved in allowing the deserialization of Object type fields in XStream, combined with them ending up handling requests.

As an improvement, Jenkins should refuse to deserialize Object fields by default.

Upstream changes

No response

Are you interested in contributing this feature?

No response

Metadata

Metadata

Assignees

Labels

No labels
No labels
No fields configured for Enhancement.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions