120340 adavis: Merged 5.0.N (5.0.4) to 5.1.N (5.1.1)
120335 adavis: Merged V4.2-BUG-FIX (4.2.6) to 5.0.N (5.0.4)
120325 cturlica: MNT-15399: Need to be able to turn off vulnerable classes bootstrap check
- new alfresco global property added (default is true): unserializer.validator.enabled
git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/HEAD/root@123617 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261
119079 adavis: Merged 5.1.N (5.1.1) to 5.1-MC1 (5.1.0)
118314 nsmintanca: Merged 5.0.N (5.0.4) to 5.1.N (5.1.1)
118271 adavis: Merged 5.0.2-CLOUD42 (Cloud ) to 5.0.N (5.0.4)
118270 adavis: Merged 5.0.2-CLOUD (Cloud ) to 5.0.2-CLOUD42 (Cloud )
118269 adavis: Merged 5.0.2-PLUS (5.0.2-PLUS) to 5.0.2-CLOUD (Cloud )
118268 adavis: Reverse merged 5.0.2-PLUS (5.0.2-PLUS)
<< Caused lots of failures with the real fix rather than the patched one in 39.6.6 >>
118213 adavis: Merged CLOUD39.6 (Cloud 39.6.6) to 5.0.2-PLUS (5.0.2-PLUS)
116649 cturlica: MNT-15229/MNT-15170: [Security] Java unserialize remote code execution
- added bootstrap unserializer validator: a bootstrap bean that checks that the classes that would favor Java unserialize remote code execution are not available. Check is needed because libs could be introduced by the application server (attached jars should be uploaded).
git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/HEAD/root@119918 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261
119078 adavis: Merged 5.1.N (5.1.1) to 5.1-MC1 (5.1.0)
118305 nsmintanca: Merged 5.0.N (5.0.4) to 5.1.N (5.1.1)
118217 adavis: Merged V4.2-BUG-FIX (4.2.6) to 5.0.N (5.0.4)
118216 adavis: Merged 5.0.2-CLOUD42 (Cloud ) to V4.2-BUG-FIX (4.2.6)
118215 adavis: Merged 5.0.2-CLOUD (Cloud ) to 5.0.2-CLOUD42 (Cloud )
118214 adavis: Merged 5.0.2-PLUS (5.0.2-PLUS) to 5.0.2-CLOUD (Cloud )
118213 adavis: Merged CLOUD39.6 (Cloud 39.6.6) to 5.0.2-PLUS (5.0.2-PLUS)
116649 cturlica: MNT-15229/MNT-15170: [Security] Java unserialize remote code execution
- added bootstrap unserializer validator: a bootstrap bean that checks that the classes that would favor Java unserialize remote code execution are not available. Check is needed because libs could be introduced by the application server (attached jars should be uploaded).
git-svn-id: https://svn.alfresco.com/repos/alfresco-enterprise/alfresco/HEAD/root@119917 c4b6b30b-aa2e-2d43-bbcb-ca4b014f7261