This commit is contained in:
Arthur Baars
2020-04-24 18:56:38 +02:00
parent fcc2b66d1a
commit 797721cd31
3 changed files with 19 additions and 0 deletions

View File

@@ -0,0 +1,12 @@
import java.io.IOException;
import java.io.ObjectInputStream;
import org.apache.commons.io.serialization.ValidatingObjectInputStream;
class Test {
public void test() throws IOException, ClassNotFoundException {
ObjectInputStream objectStream = new ObjectInputStream(null);
ObjectInputStream validating = new ValidatingObjectInputStream(null);
objectStream.readObject();
validating.readObject();
}
}

View File

@@ -0,0 +1 @@
| Test.java:9:3:9:27 | readObject(...) | ObjectInputStream |

View File

@@ -0,0 +1,6 @@
import default
import semmle.code.java.security.UnsafeDeserialization
from Method m, MethodAccess ma
where ma.getMethod() = m and unsafeDeserialization(ma, _)
select ma, m.getDeclaringType().getName()