4 ms·
Elasticsearch is actually using SecurityManager with quite thoroughly locked down policies; and it seems that this actually saved ES from being vulnerable to th
by nibix 5y ago
Elasticsearch is actually using SecurityManager with quite thoroughly locked down policies; and it seems that this actually saved ES from being vulnerable to the RCE.
The irony is now that OpenJDK just recently decided to deprecate the SecurityManager in Java 17 and remove it in Java 18.
See also this Twitter thread: https://twitter.com/rcmuir/status/1469730949810339843 https://twitter.com/rcmuir/status/1469730949810339843