blob: 4f2d11c86b43f0dceff36d432a9b3d7d5649bfa7 [file] [view] [edit]
The Java `Serializable` API is very powerful, and very dangerous. Any
consumption of a serialized object that cannot be explicitly trusted will likely
result in a critical remote code execution bug that will give an attacker
control of the application. (See
[Effective Java 3rd Edition ยง85][ej3e-85])
[ej3e-85]: https://www.google.co.uk/books/edition/Effective_Java/ka2VUBqHiWkC
Consider using less powerful serialization methods, such as JSON or XML.