tree: 6fcac2f54b0c7211ecc864c3e14963157067b1fc [path history] [tgz]
  1. src/
  2. case-configuration.yml
  3. case-versions.conf
  4. pom.xml
  5. README.md
3-extensions/registry/dubbo-samples-default-config/README.md

dubbo-samples-default-config

Security warning

Warning: this sample includes the dubbo-rpc-hessian component, but does not configure a deserialization whitelist. This means it should never be deployed in a way that allows untrusted access without first configuring a deserialization whitelist.

https://dubbo.apache.org/en/docs/notices/security/#some-suggestions-to-deal-with-the-security-vulnerability-of-deserialization