Restrict classes allowed for cluster config and event types (#18165) #18179
+429
−30
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Add a new safe_classes configuration option to restrict the classes allowed to be used as cluster config and event types.
The configuration option allows to specify a comma-separated set of prefixes matched against the fully qualified class name.
For now, the default value for the configuration is org.graylog.,org.graylog2., which will allow all classes that Graylog maintains.
This should work out of the box for almost all setups. Changing the default value might only be necessary if external plugins require cluster config or event types outside the "org.graylog." or "org.graylog2." namespaces. If that is the case, the configuration setting can be adjusted to cover this use case, e.b. by setting it to
if said classes are located within the custom.plugin.namespace package.
Refs: GHSA-p6gg-5hf4-4rgj
(cherry picked from commit 8132032)