/[Apache-SVN]
ViewVC logotype

Revision 1735569


Jump to revision: Previous Next
Author: jleroux
Date: Fri Mar 18 10:38:04 2016 UTC (8 years, 1 month ago)
Changed paths: 5
Log Message:
Fixes "Comment out RMI related code because of the Java deserialization issue" - https://issues.apache.org/jira/browse/OFBIZ-6942

I decided to comment out as less as possible because once the RMI loaders, the RMI dispatcher and the related test services are off there is no RMI related danger left (test services are not a danger but would fail during tests run). It's then easier for users who need RMI in their projects to have only to uncomment those and not digg everywhere. Because the naming (JNDI) server relies on the rmi loader it will also be commented out.

[CVE-2016-2170] The infamous Java serialization vulnerability

Changed paths

Path Details
Directoryofbiz/trunk/framework/base/config/ofbiz-containers.xml modified , text changed
Directoryofbiz/trunk/framework/base/ofbiz-component.xml modified , text changed
Directoryofbiz/trunk/framework/common/servicedef/services_test.xml modified , text changed
Directoryofbiz/trunk/framework/service/ofbiz-component.xml modified , text changed
Directoryofbiz/trunk/framework/start/src/org/ofbiz/base/start/both.properties modified , text changed

infrastructure at apache.org
ViewVC Help
Powered by ViewVC 1.1.26