alibaba / alibaba/jetcache

kryo 4.0.0 BDSA-2016-1151 漏洞 Kryo JAVA serialization API may be leveraged to perform denial-of-service (DoS) attack, memory corruption and eventually remote code execution (RCE) attacks due to not enforcing white-listing (class registration) by default when deserializing.

Open
#561 2 comments 0 reactions 0 assignees View on GitHub
Dominant language
Java
Stars
5.6k
Forks
1.1k
PR merge metrics
No merged PRs in 30d

Description

This issue has no description.

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names Kryo 4.0.0 and Java serialization but provides no files, tests, or requested change. Start by locating Kryo deserialization entry points in the JetCache Java source and determine how class registration is handled. Done should mean the reported vulnerability is addressed and its behavior is covered by regression testing.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.