Hessian
SOFA-Hessian
增加 泛化序列 化 。增加 ClassNameResolver
和 ClassNameFilter
用 于类名 的 映 射 、转换、过滤等 。增加 序列 化 黑 名 单(来 自 蚂蚁金 服 安全 团队)。改 进SerializerFactory
内 缓存的 锁机制 。更 多 参 见:改 进点。
- JDK 6 及以
上 。
Hessian
Hessian is a binary serialization protocol.
Because of the implement of Hessian, by constructing a specific serialization stream, it may cause arbitrary code execution when doing deserialization. It is recommended that users configure blacklist or whitelist to solve the problem.
The blacklist built into the project comes from internal practices and external contributions, and is for reference only and is not actively updated, we do not assume any legal responsibility for this. For more rigorous verification, please use the whitelist feature.