Skip to content

Actual CVE-2018-8088 issue? #291

Answered by ceki
ecki asked this question in Q&A
Jun 30, 2022 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

EventData was serializable. Moreover, its deserialization offered no safety checks. If I remember correctly, it could this be used to mount deserialization attacks using malicious data.

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@ecki
Comment options

Answer selected by ceki
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants