2 ms·
There's two problems with the lookahead approach: 1) It only applies to the code you write. Libraries can still use insecure object serialization under the ho
by wsargent 11y ago
There's two problems with the lookahead approach:
1) It only applies to the code you write. Libraries can still use insecure object serialization under the hood i.e. you can't apply this to an built in app server running JMX.
2) It doesn't account for pathological objects, i.e. a billion laughs attack: https://gist.github.com/coekie/a27cc406fc9f3dc7a70d https://gist.github.com/coekie/a27cc406fc9f3dc7a70d
More details here: https://tersesystems.com/2015/11/08/closing-the-open-door-of-java-object-serialization/ https://tersesystems.com/2015/11/08/closing-the-open-door-of...