Home / Vulnerability Database / Scala : Deserialization of untrusted data
Scala

Scala : Deserialization of untrusted data

Overview

Deserialization of user-controlled objects can lead to arbitrary code execution on the server.

Deserializing objects from a standard thread is insecure, because an attacker can override the contents and cause the application to execute arbitrary code. Even if you check the types after deserialization, the malicious code can already be executed, since it happens during deserialization.

MEDIUM

DerScanner Severity Score

Do you want to fix Scala : Deserialization of untrusted data in your application?

See also

Scala

Scala : Unreleased resource stream

Scala

Scala : Multiple loggers in same class

Scala

Scala : Insufficient encryption key length