CVE-2021-29505

Deserialization exploit

Reproducing and analyzing the CVE-2021-29505 vulnerability in Java's XStream deserialization process

对CVE-2021-29505进行复现,并分析学了下Xstream反序列化过程

GitHub

5 stars
2 watching
2 forks
Language: Java
last commit: over 5 years ago

Related projects:

RepositoryDescriptionStars
babyteam1024/cve-2021-2394An exploit for a Java vulnerability9
danigargu/cve-2020-0796An exploit tool for a Windows SMBv3 vulnerability1,303
y4er/cve-2020-2883Exploits a remote code execution vulnerability in WebLogic Coherence using Java178
leadroyal/cve-2019-14540-exploitAn exploit for a Java-based LDAP vulnerability20
darryk10/cve-2021-25735An exploit demonstrating a Kubernetes validation admission webhook bypass vulnerability18
bishopfox/gadgetprobeTools for analyzing and exploiting vulnerabilities in Java deserialization vulnerabilities587
vysecurity/cve-2018-4878Exploits a vulnerability in outdated Shockwave Flash player to gain control of Internet Explorer and execute malicious code.87
joaomatosf/javadeserh2hcA lab project providing code samples and tools to understand deserialization vulnerabilities in Java applications.497
jas502n/jackson-cve-2020-8840A project that details and demonstrates the impact of a remote code execution vulnerability in a popular Java library used for JSON data binding.73
r3dxpl0it/cve-2018-4407Exploits a heap buffer overflow vulnerability in the XNU operating system kernel to cause a denial-of-service attack on iOS and macOS devices.35
nccgroup/freddyA tool to detect and exploit deserialization vulnerabilities in Java and .NET applications.574
jas502n/cve-2019-12384A proof-of-concept project demonstrating a Jackson RCE vulnerability in Ruby that allows an attacker to execute arbitrary commands on the system.97
rsmudge/cve-2020-0796-bofExploits a vulnerability in SMBv3 compression to achieve privilege escalation and process manipulation.68
mogwailabs/rmi-deserializationDemonstrating vulnerabilities in Java RMI services101
directdefense/superserialA Burp Suite Extender to identify Java Deserialization vulnerabilities in client requests and server responses.9