Fixed: Adds a blacklist (to be renamed soon to denylist) in Java seri…
…alisation (OFBIZ-12167)

Adds an example based on RMI which is known to be a problem
JacquesLeRoux committed Feb 5, 2021
1 parent 11634ae commit af9ed4e
Expand Up @@ -62,9 +62,18 @@ public SafeObjectInputStream(InputStream in) throws IOException {

protected Class<?> resolveClass(ObjectStreamClass classDesc) throws IOException, ClassNotFoundException {
if (!whitelistPattern.matcher(classDesc.getName()).find()) {
String className = classDesc.getName();
// BlackList exploits; eg: don't allow RMI here
if (className.contains("java.rmi.server")) {
Debug.logWarning("***Incompatible class***: "
+ classDesc.getName()
+ ". java.rmi.server classes are not allowed for security reason",
return null;
if (!whitelistPattern.matcher(className).find()) {
// DiskFileItem, FileItemHeadersImpl are not serializable.
if (classDesc.getName().contains("org.apache.commons.fileupload")) {
if (className.contains("org.apache.commons.fileupload")) {
return null;
Debug.logWarning("***Incompatible class***: "
