Skip to content
This repository has been archived by the owner on Feb 23, 2025. It is now read-only.

Use SimpleEvaluationContext instead of StandardEvaluationContext #126

Merged
merged 1 commit into from
Feb 5, 2024

Conversation

Linfar
Copy link
Contributor

@Linfar Linfar commented Feb 1, 2024

StandardEvaluationContext allows arbitrary code, including Runtime class which in its turn can lead to an RCE. Eg https://codethreat.medium.com/reminiscences-of-another-el-injection-62a3335cd22.

It looks like SimpleEvaluationContext can be safely used instead.

@morincer morincer merged commit 929f7a1 into morincer:master Feb 5, 2024
1 check passed
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants