Top 10 winner
Friday-The-13th-JSON-Attacks-wp.pdf
Shows that switching from Java or .NET binary serialization to JSON does not remove deserialization risk: libraries that embed type discriminators will instantiate attacker-chosen types and call their setters, constructors and type converters. The paper catalogues vulnerable Java and .NET JSON libraries and supplies gadget chains that reach remote code execution.
Record
- Researcher
- Alvaro Muñoz and Oleksandr Mirosh
- Published by
- HPE Software Security Research
- Format
- Whitepaper
In the archive
Tags
This page is the archive's own catalogue record. The research is the work of Alvaro Muñoz and Oleksandr Mirosh, first published at the original source. Preserved copies are kept so the citation survives its host.