jackson-rce-via-spel
jackson-rce-via-spel copied to clipboard
An example project that exploits the default typing issue in Jackson-databind via Spring application contexts and expressions
Results
1
jackson-rce-via-spel issues
Sort by
recently updated
recently updated
newest added
Like this: creating objectmapper Exception in thread "main" com.fasterxml.jackson.databind.exc.InvalidTypeIdException: Could not resolve type id 'org.springframework.context.support.FileSystemXmlApplicationContext' as a subtype of [simple type, class java.lang.Object]: no such class found at [Source: (String)"{"id":123,...