Summary

In Spring for Apache Kafka, overly broad trusted-package matching in header mappers exposes JDK classes to deserialization

References