How does Spring prevents request body deserialization attacks?

106 views Asked by At

I have read about deserialization attacks recently and I wonder how does Spring prevent JSON injections. For example let’s consider a request body of a post request, we can instantiate an arbitrary malicious class and execute commands on the server. Are there any mechanisms that check for malicious behavior?

I expect Jackson or other libraries solved these kind of problems.

0

There are 0 answers