Yeah, let's just trust the input stream to *tell us* what class of object to deserialise. What's the worst that c-- https://blogs.apache.org/foundation/entry/apache_commons_statement_to_widespread …
-
-
Replying to @qntm
The real culprit here is ObjectInputStream.readObject(), which ought to be parameterised with the desired class instead of requiring a cast
1 reply 1 retweet 2 likes
At least that way your attack surface doesn't consist of every readObject implementation in every class in every library you use
0 replies
1 retweet
3 likes
Loading seems to be taking a while.
Twitter may be over capacity or experiencing a momentary hiccup. Try again or visit Twitter Status for more information.