Skip to content

Conversation

@setuper
Copy link

@setuper setuper commented Apr 2, 2025

This class can be used as a gadget for attack. It is suggested to make a setting to disable potentially dangerous code

@ddekany
Copy link
Contributor

ddekany commented Apr 4, 2025

Creating an instance of this TemplateModel from templates is disabled by default already (see TemplateClassResolver.SAFER_RESOLVER). So I'm note sure how much this helps in practice, as this doesn't block by default, and people had to realize that the problem exist at all, and then that there's a system property to block it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants