tree: b93abdb5e6a0cb27447fbde638d4bf97c2108c21 [path history] [tgz]
  1. src/
  2. case-configuration.yml
  3. case-versions.conf
  4. pom.xml
  5. README.md
3-extensions/registry/dubbo-samples-default-config/README.md

dubbo-samples-default-config

Security warning

Warning: this sample includes the dubbo-rpc-hessian component, but does not configure a deserialization whitelist. This means it should never be deployed in a way that allows untrusted access without first configuring a deserialization whitelist.

https://dubbo.apache.org/en/docs/notices/security/#some-suggestions-to-deal-with-the-security-vulnerability-of-deserialization