Skip to content

Latest commit

 

History

History
4 lines (4 loc) · 279 Bytes

File metadata and controls

4 lines (4 loc) · 279 Bytes
category minorAnalysis
  • The qualifiers of a calls to readObject on any classes that implement java.io.ObjectInput are now recognised as sinks for java/unsafe-deserialization. Previously this was only the case for classes which extend java.io.ObjectInputStream.