Skip to content

CodeQL - Unsafe Deserialization #296

Answered by hvitved
mwest67 asked this question in General
Discussion options

You must be logged in to vote

Your second gist looks better, as the sink is not the GetType() call itself, but rather the argument to GetType().

I don't understand isSource: It is defined as all remote entry points that are directly passed to XmlDocument.Load, is that the intention?

Replies: 1 comment 4 replies

Comment options

You must be logged in to vote
4 replies
@mwest67
Comment options

@hvitved
Comment options

hvitved Mar 8, 2021
Collaborator

@pwntester
Comment options

@RasmusWL
Comment options

Answer selected by RasmusWL
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
4 participants