Quantcast
Channel: Issues for Drupal core
Viewing all articles
Browse latest Browse all 295813

Clean up unserialize() in the config system

$
0
0

Background information

This was originally logged as a private issue to the security team, but was cleared to be moved to the public queue

Problem/Motivation

The unserialize() function should never be used without specifying allowed classes.

Proposed resolution

Remaining tasks

User interface changes

None

Introduced terminology

None

API changes

None

Data model changes

None

Release notes snippet

N/A


Viewing all articles
Browse latest Browse all 295813

Trending Articles