Skip to content

Conversation

setuper
Copy link

@setuper setuper commented Apr 2, 2025

This class can be used as a gadget for attack. It is suggested to make a setting to disable potentially dangerous code

@ddekany
Copy link
Contributor

ddekany commented Apr 4, 2025

Creating an instance of this TemplateModel from templates is disabled by default already (see TemplateClassResolver.SAFER_RESOLVER). So I'm note sure how much this helps in practice, as this doesn't block by default, and people had to realize that the problem exist at all, and then that there's a system property to block it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants