Merge pull request #5881 from haby0/java/UnsafeDeserialization

Java: CWE-502 Add UnsafeDeserialization sinks
This commit is contained in:
Anders Schack-Mulligen
2021-06-17 12:36:34 +02:00
committed by GitHub
39 changed files with 2073 additions and 3 deletions

View File

@@ -0,0 +1,3 @@
lgtm,codescanning
* The "Deserialization of user-controlled data" (`java/unsafe-deserialization`) query
now recognizes `JYaml`, `JsonIO`, `YAMLBeans`, `Castor`, `Hessian` and `Burlap` deserialization.