mgonzalezcx / WebGoat

WebGoat is a deliberately insecure application
https://webgoat.github.io/WebGoat/
Other
0 stars 0 forks source link

CX Deserialization_of_Untrusted_Data @ webgoat-lessons/insecure-deserialization/src/main/java/org/owasp/webgoat/deserialization/InsecureDeserializationTask.java [develop] #28

Open mgonzalezcx opened 2 years ago

mgonzalezcx commented 2 years ago

Deserialization_of_Untrusted_Data issue exists @ webgoat-lessons/insecure-deserialization/src/main/java/org/owasp/webgoat/deserialization/InsecureDeserializationTask.java in branch develop

The serialized object token processed in completed in the file webgoat-lessons\insecure-deserialization\src\main\java\org\owasp\webgoat\deserialization\InsecureDeserializationTask.java at line 46 is deserialized by readObject in the file webgoat-lessons\insecure-deserialization\src\main\java\org\owasp\webgoat\deserialization\InsecureDeserializationTask.java at line 46.

Severity: High

CWE:502

Vulnerability details and guidance

Internal Guidance

Checkmarx

Training Recommended Fix

Lines: 46


Code (Line #46):

    public AttackResult completed(@RequestParam String token) throws IOException {