[rules-users] Drools6.0 Security Issues

18922445710 18922445710 at 189.cn
Fri Dec 27 04:19:58 EST 2013


Hello, everyone,
Greetings!

 I want to use Drools6.0 in my project,but I found a security issue. The Drools6.0 automatically import the java.lang.* packages.
As we all know, thess packages including some package such as Process class,which can damage the application's  security.
So, I want know how to prohibit some package  from executing in rule configure file(including drl,decistion tablea)  or program code.
Thank you everyone .

  With my best wishes!
                                                                                                                    Sincerely yours,     philip
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/rules-users/attachments/20131227/25ef3bd6/attachment.html 


More information about the rules-users mailing list