view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon
view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon
view.getClass().forName('java.lang.Runtime'). - 2010 - Ruxcon
- No tags were found...
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
CVE-<strong>2010</strong>-1622 fixProper fix is to use Introspector API correctly andspecify the stop class:Introspector.getBeanInfo(Person.class, Object.class);Other projects may be vulnerable to this bug too.Spring disallows access to class.classLoaderFixed in the following versions:Spring Framework 3.0.3/2.5.6.SEC02/2.5.7.SR01Thursday, November 25, <strong>2010</strong>