kryo 4.0.0 BDSA-2016-1151 漏洞 Kryo JAVA serialization API may be leveraged to perform denial-of-service (DoS) attack, memory corruption and eventually remote code execution (RCE) attacks due to not enforcing white-listing (class registration) by default when deserializing.
Open
- Dominant language
- Java
- Stars
- 5.6k
- Forks
- 1.1k
- PR merge metrics
- No merged PRs in 30d
Description
This issue has no description.
Contributor guide
No contributing guide indexed for this repository
Research direction
The issue names Kryo 4.0.0 and Java serialization but provides no files, tests, or requested change. Start by locating Kryo deserialization entry points in the JetCache Java source and determine how class registration is handled. Done should mean the reported vulnerability is addressed and its behavior is covered by regression testing.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- java
- Domain
- security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100