An uncertain security problem

Skip to first unread message


Feb 17, 2023, 3:13:50 AM2/17/23
to pf4j
    By default in all versions of pf4j, when the plugin file: jar package or zip package are controlled by the user, the user can construct malicious files to execute arbitrary code in the web application through the pf4j declaration cycle function. I'm not sure whether pf4j should control this, so I'm here to ask you whether this is a security vulnerability
    I can't find other places to ask about security issues, so I can only send it here. I hope you forgive me
Reply all
Reply to author
0 new messages