Insecure deserialization¶
Insecure deserialization.
Retired. This entry was not a citation. Our extractor stored an inline prose definition from the article as though it were a bibliographic record: the title names a concept rather than a published work, and the citation text names no work at all. The page is kept because links to it still resolve, but it is withdrawn from the reference list. This entry is kept so the citations that pointed at it still resolve, and so the correction is visible rather than silent.
Cited by¶
1 citation across 1 artifact.
Each citation links to the sentence it supports in the citing article.
Mechanisms¶
- Schema-Validated Message Envelope
- A related trap is a permissive deserializer that reconstructs objects from the payload, reintroducing insecure deserialization beneath a tidy-looking envelope.
This sourceA schema that validates field types can still sit atop a deserializer that instantiates arbitrary types, which is why envelope validation must not be conflated with safe deserialization.
- A related trap is a permissive deserializer that reconstructs objects from the payload, reintroducing insecure deserialization beneath a tidy-looking envelope.
Verification¶
This reference passed the adversarial substantiation pipeline: it was checked to exist and to support the claim it is attached to. See how references were verified.
Registry ID ref:a4bc138e5704 · see in the full table