Uploaded image for project: 'River'
  1. River
  2. RIVER-362

Denial of Service during unmarshalling of smart proxy's

    Details

    • Type: Bug
    • Status: Open
    • Priority: Major
    • Resolution: Unresolved
    • Affects Version/s: None
    • Fix Version/s: None
    • Component/s: None
    • Labels:
      None
    • Environment:

      Untrusted networks

      Description

      During unmarshalling of smart proxy's there's a period before the proxy has been verified (authenticated) where deserialization methods are executed on untrusted code, the potential exists for untrusted code to perform denial of service.

        Attachments

        1. river-modules.zip
          92 kB
          Michal Kleczek

          Issue Links

            Activity

              People

              • Assignee:
                Unassigned
                Reporter:
                pfirmst Peter Firmstone
              • Votes:
                0 Vote for this issue
                Watchers:
                1 Start watching this issue

                Dates

                • Created:
                  Updated: