2 ms·
To sum up your link, the vulnerability is the use of an unsafe deserialization similar to: ObjectInputStream ois = new ObjectInputStream(input); MyObje
by olivier1664 9y ago
To sum up your link, the vulnerability is the use of an unsafe deserialization similar to:
ObjectInputStream ois = new ObjectInputStream(input);
MyObject obj = (MyObject)ois.readObject();
https://lgtm.com/blog/finding_unsafe_deserialization_with_ql https://lgtm.com/blog/finding_unsafe_deserialization_with_ql