PayPal: Lessons Learned from the Java Deserialization Bug paypal-engineering.com/2016/… < now this is how things should be done
1
16
10
I don't understand this... "We found we were not exercising the vuln classes in apache-commons -> no immediate risk" @jeremiahg @paypaleng
3
Replying to @jeremiahg
@jeremiahg @planetlevel @paypaleng It means the code had vulnerable class, but class was not used.

Feb 1, 2016 · 7:44 PM UTC

2
Replying to @bilcorry
@bilcorry @jeremiahg @planetlevel @paypaleng Oh, I meant to say that we were NOT using any of the vulnerable classes in our core frameworks
1
1
1
Replying to @bilcorry
@bilcorry @jeremiahg @paypaleng that's how I read it too, but they'd still be vulnerable. Deserialization constructs arbitrary classes