Skip to content

Review jmxreceiver from a security perspective #6750

@Aneurysm9

Description

@Aneurysm9

jmxreceiver allows executing Java applications and accepts the JAR to execute as well as arbitrary Groovy script.

This is potentially a security problem, especially coupled with upcoming remote configuration capabilities. We need to make sure the Collector cannot be compelled to execute arbitrary code.

See also: #6721 #6722

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions