Files
codeql/csharp/ql/test/query-tests/Security Features/CWE-502/UnsafeDeserializationUntrustedInput/BinaryFormatterUntrustedInputGood.cs
2021-03-20 21:50:46 +02:00

14 lines
314 B
C#

using System.Runtime.Serialization.Formatters.Binary;
using System.IO;
using System.Text;
class GoodBinaryFormatter
{
public static object Deserialize()
{
var ds = new BinaryFormatter();
// GOOD
return ds.Deserialize(new MemoryStream(Encoding.UTF8.GetBytes("hardcoded")));
}
}