diff --git a/pom.xml b/pom.xml index ab506b8..d74b045 100644 --- a/pom.xml +++ b/pom.xml @@ -14,7 +14,7 @@ org.springframework.boot spring-boot-starter-parent - 2.5.11 + 2.5.12 diff --git a/src/main/java/de/koudingspawn/vault/config/GlobalControllerAdvice.java b/src/main/java/de/koudingspawn/vault/config/GlobalControllerAdvice.java deleted file mode 100644 index 94e339d..0000000 --- a/src/main/java/de/koudingspawn/vault/config/GlobalControllerAdvice.java +++ /dev/null @@ -1,19 +0,0 @@ -package de.koudingspawn.vault.config; - -import org.springframework.core.annotation.Order; -import org.springframework.web.bind.WebDataBinder; -import org.springframework.web.bind.annotation.ControllerAdvice; -import org.springframework.web.bind.annotation.InitBinder; - -// https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html -@ControllerAdvice -@Order(10000) -public class GlobalControllerAdvice { - - @InitBinder - public void setAllowedFields(WebDataBinder dataBinder) { - String[] abd = new String[]{"class.*", "Class.*", "*.class.*", "*.Class.*"}; - dataBinder.setDisallowedFields(abd); - } - -} \ No newline at end of file