首页 > 解决方案 > How to resolve Deserialization of untrusted data checkmarx scan issue

问题描述

I have an checkmarx high defect to resolve deserialization of untrusted data.

Here is my code

File file = new File(path);
FileInputStream fin = new FileInputStream(file):
ObjectInputStream ois = new ObjectInputStream(fin);
Object result = ois.readObject();
ois.close();

标签: javacheckmarx

解决方案


推荐阅读