Completed
Details
Assignee
UnassignedUnassignedReporter
Tim McCormack [personal]Tim McCormack [personal]Approval
VettedPatch
CodePriority
TrivialAffects versions
Details
Details
Assignee
Unassigned
UnassignedReporter
Tim McCormack [personal]
Tim McCormack [personal]Approval
Vetted
Patch
Code
Priority
Affects versions
Created December 31, 2011 at 3:39 PM
Updated February 22, 2013 at 3:02 PM
Resolved February 22, 2013 at 3:02 PM
Even though the #=() reader syntax is "unofficial", *read-eval* should be documented in the appropriate API functions – this is a serious security problem for anyone accepting serialized Clojure data structures. E.g., a system service reading a config file, a server accepting an API request.