Skip to content

Remove Java deserialization from JWT authentication#755

Open
yannaingtun wants to merge 1 commit intoManyDesigns:masterfrom
yannaingtun:fix/jwt-deserialization
Open

Remove Java deserialization from JWT authentication#755
yannaingtun wants to merge 1 commit intoManyDesigns:masterfrom
yannaingtun:fix/jwt-deserialization

Conversation

@yannaingtun
Copy link

This PR removes unsafe Java object deserialization from JWT authentication.
JWTs now carry only a principal identifier, and the principal is reconstructed
server-side, eliminating insecure deserialization and classloader abuse
risks (CWE-502).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant