[jboss-jira] [JBoss JIRA] Commented: (GPD-278) Security issue allows arbitrary java code to be deployted and executed

Thomas Diesler (JIRA) jira-events at lists.jboss.org
Mon Dec 15 03:39:36 EST 2008


    [ https://jira.jboss.org/jira/browse/GPD-278?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=12442490#action_12442490 ] 

Thomas Diesler commented on GPD-278:
------------------------------------

Please have look at the IntegrationTestHelper. It demonstrates how to obtain a MBeanServerConnection and deployes a file through the MainDeployer

> Security issue allows arbitrary java code to be deployted and executed
> ----------------------------------------------------------------------
>
>                 Key: GPD-278
>                 URL: https://jira.jboss.org/jira/browse/GPD-278
>             Project: JBoss jBPM GPD
>          Issue Type: Bug
>          Components: jpdl
>            Reporter: Thomas Diesler
>            Assignee: Koen Aers
>
> The GPD circumvents the JBoss deployer architecture and hence allows arbitrary code to be executed on the AS

-- 
This message is automatically generated by JIRA.
-
If you think it was sent incorrectly contact one of the administrators: https://jira.jboss.org/jira/secure/Administrators.jspa
-
For more information on JIRA, see: http://www.atlassian.com/software/jira

        



More information about the jboss-jira mailing list