forked from BroadleafCommerce/BroadleafCommerce
-
Notifications
You must be signed in to change notification settings - Fork 1
Pull requests: COG-GTM/BroadleafCommerce
Author
Label
Projects
Milestones
Reviews
Assignee
Sort
Pull requests list
Filtering classes during Zookeeper distributed queue deserialization (CWE-502)
#117
opened Sep 14, 2026 by
Colhodm
Loading…
bug: restrict Java deserialization in ZookeeperDistributedQueue (CWE-502)
#116
opened Sep 10, 2026 by
Colhodm
Loading…
Restricting ZookeeperDistributedQueue deserialization to an allowlist (CWE-502)
#115
opened Sep 9, 2026 by
Colhodm
Loading…
Adding ObjectInputFilter allowlist to ZookeeperDistributedQueue deserialization (CWE-502)
#114
opened Sep 7, 2026 by
Colhodm
Loading…
Restrict Java deserialization in ZookeeperDistributedQueue (CWE-502)
#113
opened Sep 3, 2026 by
Colhodm
Loading…
Restrict class deserialization in ZookeeperDistributedQueue (CWE-502)
#112
opened Sep 2, 2026 by
Colhodm
Loading…
Restricting classes allowed when deserializing Zookeeper distributed queue entries
#111
opened Aug 31, 2026 by
Colhodm
Loading…
Restricting classes accepted during Zookeeper distributed queue deserialization (CWE-502)
#110
opened Aug 27, 2026 by
Colhodm
Loading…
Re-validating the admin login redirect target to prevent open redirect
#109
opened Aug 27, 2026 by
devin-ai-integration
Bot
Loading…
Restricting the classes that can be deserialized from Zookeeper queues
#108
opened Aug 26, 2026 by
Colhodm
Loading…
Restrict ZookeeperDistributedQueue deserialization with an allow-list ObjectInputFilter
#107
opened Aug 20, 2026 by
Colhodm
Loading…
Prevent open redirect via failureUrl/successUrl on admin login failure
#106
opened Aug 20, 2026 by
devin-ai-integration
Bot
Loading…
Sandboxing MVEL rule evaluation to prevent remote code execution via rule injection
#105
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: prevent path traversal / arbitrary file write in admin asset upload
#104
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: reject path traversal in uploaded asset file names and asset writes
#103
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
bug: sanitize static asset fullUrl and validate stored file extension
#102
opened Aug 19, 2026 by
devin-ai-integration
Bot
Loading…
Restrict Zookeeper queue deserialization with an allow-list ObjectInputFilter
#101
opened Aug 19, 2026 by
Colhodm
Loading…
Restricting ZookeeperDistributedQueue deserialization to an allow list of classes
#100
opened Aug 17, 2026 by
Colhodm
Loading…
Restricting Zookeeper distributed queue deserialization to an allow-listed set of types
#99
opened Aug 13, 2026 by
Colhodm
Loading…
Fixing admin entity authorization bypass via client-controlled sectionCrumbs
#97
opened Aug 13, 2026 by
kevinlrd
Loading…
Removing raw MVEL fallback when persisting quantity-based rule match rules
#96
opened Aug 13, 2026 by
kevinlrd
Loading…
Restricting Zookeeper queue deserialization to an allow list of types (CWE-502)
#95
opened Aug 12, 2026 by
Colhodm
Loading…
Restrict ZookeeperDistributedQueue deserialization with an allow-list ObjectInputFilter
#94
opened Aug 10, 2026 by
Colhodm
Loading…
Strip path traversal from uploaded asset file names
#93
opened Aug 7, 2026 by
devin-ai-integration
Bot
Loading…
Previous Next
ProTip!
Filter pull requests by the default branch with base:develop-7.0.x.