[rules-users] Drools6.0 Security Issues
18922445710
18922445710 at 189.cn
Fri Dec 27 04:19:58 EST 2013
Hello, everyone,
Greetings!
I want to use Drools6.0 in my project,but I found a security issue. The Drools6.0 automatically import the java.lang.* packages.
As we all know, thess packages including some package such as Process class,which can damage the application's security.
So, I want know how to prohibit some package from executing in rule configure file(including drl,decistion tablea) or program code.
Thank you everyone .
With my best wishes!
Sincerely yours, philip
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://lists.jboss.org/pipermail/rules-users/attachments/20131227/25ef3bd6/attachment.html
More information about the rules-users
mailing list