Merge pull request #3215 from aibaars/validating-object-input

Java: teach UnsafeDeserialization about ValidatingObjectInputStream
This commit is contained in:
Anders Schack-Mulligen
2020-05-07 14:57:50 +02:00
committed by GitHub
4 changed files with 27 additions and 1 deletions

View File

@@ -0,0 +1,12 @@
import java.io.IOException;
import java.io.ObjectInputStream;
import org.apache.commons.io.serialization.ValidatingObjectInputStream;
class Test {
public void test() throws IOException, ClassNotFoundException {
ObjectInputStream objectStream = new ObjectInputStream(null);
ObjectInputStream validating = new ValidatingObjectInputStream(null);
objectStream.readObject();
validating.readObject();
}
}

View File

@@ -0,0 +1 @@
| Test.java:9:3:9:27 | readObject(...) | ObjectInputStream |

View File

@@ -0,0 +1,6 @@
import default
import semmle.code.java.security.UnsafeDeserialization
from Method m, MethodAccess ma
where ma.getMethod() = m and unsafeDeserialization(ma, _)
select ma, m.getDeclaringType().getName()