The real culprit here is ObjectInputStream.readObject(), which ought to be parameterised with the desired class instead of requiring a cast
-
-
-
At least that way your attack surface doesn't consist of every readObject implementation in every class in every library you use
End of conversation
New conversation -
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.