Home / Vulnerability Database / Scala : No SecurityManager checks in deserialization methods
Scala

Scala : No SecurityManager checks in deserialization methods

Overview

Security checks via SecurityManager or AccessController are present in the Serializable class constructor but not in deserialization methods.

When calling readObject() and readObjectNoData() the constructor is not called, therefore, security checks defined in the constructor will not be performed.

LOW

DerScanner Severity Score

Do you want to fix Scala : No SecurityManager checks in deserialization methods in your application?

See also

Scala

Scala : Unreleased resource stream

Scala

Scala : Multiple loggers in same class

Scala

Scala : Insufficient encryption key length