Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Up-to-date guidelines for serialization usage [DATAREDIS-780] #1356

spring-projects-issues opened this issue Mar 6, 2018 · 1 comment
type: documentation A documentation update


Copy link

Mark Paluch opened DATAREDIS-780 and commented

Over the past few years, several incidents were related to using serialization-based message formats from untrusted data sources. We need to update our guidelines accordingly. While we generally recommend against Java serialization there are some recent efforts that allow for controlled exposure there, in particular the serialization filter that recently got introduced at JDK level (

Affects: 2.1 M1 (Lovelace), 1.8.10 (Ingalls SR10), 2.0.5 (Kay SR5)

Backported to: 2.0.6 (Kay SR6), 1.8.11 (Ingalls SR11)

Copy link

Mark Paluch commented

We should reword our documentation to:

RedisCache and RedisTemplate are configured by default to use Java native serialization. Java native serialization is known for allowing remote code execution caused by payloads that exploit vulnerable libraries and classes injecting unverified bytecode. Manipulated input could lead to unwanted code execution on the server during the deserialization step. As a consequence, do not use serialization in untrusted environments. In general, we strongly recommend any other message format (e.g. JSON) instead.

If you are concerned about security vulnerabilities due to Java serialization, consider the general-purpose serialization filter mechanism at the core JVM level, originally developed for JDK 9 but backported to JDK 8, 7 and 6 in the meantime:

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
type: documentation A documentation update
None yet

No branches or pull requests

2 participants