Shashibhushan Gokhale's blog
My observations, nothing more
Search This Blog
Pages
Home
Tuesday, December 31, 2019
Jackson Java Deserialization Vulnerabilities
Very detailed information about the vulnerabilities is available
here
,
here
and
here
. To summarize, the java code is vulnerable if following strings are present in code:
enableDefaultTyping
@Json
Type
Info
(
per-class annotations
)
Newer Posts
Older Posts
Home
Subscribe to:
Comments (Atom)