Recently learning about Java deserialization vulnerabilities, I will push the vulnerability payload and vulnerability analysis articles that I have analyzed.
I will first analyze the vulnerability payload in the following Java libraries.
- Groovy
- JDK7u21
- Apache Common Collection
- Spring
- FastJson
- FastJson Basic
- FastJson TemplatesImpl
- FastJson JdbcRowSetImpl
- FastJson Bypass
- JNDI Injection
- Jackson
- XMLDecoder
- SnakeYaml
After that, I will find some deserialization vulnerabilities in practical applications for analysis.
- Java SnakeYaml反序列化
- FastJson