Insecure deserialization
Description
The system deserializes objects without first validating their content nor casting them to a specific type.
Impact
Enable to control the application execution flow.
Recommendation
Validate the incoming serialized objects and only deserialize them if they meet expected properties.
Threat
Authenticated attacker from the Internet.
Expected Remediation Time
⏱️ 30 minutes.
Rules
Python Loads Insecure DeserializationJavascript Unsafe Deserialization Untrusted DataC Sharp Jsserializer Simpletyperesolver UsageC Sharp Viewstate Deserialization Rce InsecureRuby Yaml Insecure DeserializationTypescript Unsafe Deserialization Untrusted DataPhp Untrusted Unserialize InputC Sharp Insecure Deserialization Untrusted InputPython Unsafe Deserialization MethodKotlin Insecure Deserialization Untrusted DataC Sharp Insecure Deserialization FastjsonC Sharp Insecure Fspickler DeserializationC Sharp Unsafe Xml DeserializationRuby Use Of Marshal Dangerous FunctionSwift Unarchiver Insecure DeserializationScala Untrusted Input Insecure DeserializationC Sharp Type Name Handling All