Java Deserialization Exploits: Registry Whitelist Bypass
In 2019, An Trinh discovered two vulnerabilities, CVE-2019-9670 (XXE/SSRF) and CVE-2019-6980 (deserialization vulnerability), in Zimbra. As usual, An Trinh did not disclose any details. Luckily, Hans Martin Munch is more generous than An Trinh and has shared many interesting ideas. For example, he once advised using YouDebug to fix the CVE-2017-3241 vulnerability. ysoserial.payloads.JRMPClient is designed […]






