mirror of https://github.com/apache/activemq.git
Merge pull request #697 from skyguard1/fix_xstream_xml_risk
[AMQ-8348] Fix XmlMessageRenderer has the risk of XStream deserialization
This commit is contained in:
commit
4fd439e91d
|
@ -42,6 +42,7 @@ public class XmlMessageRenderer extends SimpleMessageRenderer {
|
|||
public XStream getXstream() {
|
||||
if (xstream == null) {
|
||||
xstream = new XStream();
|
||||
XStream.setupDefaultSecurity(xstream);
|
||||
}
|
||||
return xstream;
|
||||
}
|
||||
|
|
Loading…
Reference in New Issue