• nymnympseudonym@piefed.social
    link
    fedilink
    English
    arrow-up
    5
    ·
    24 days ago

    serialized Java objects

    Any project that is using Java serialization with readObject() is inherently insecure. It blows my mind that people keep corporate secret keys in Jenkins vaults.

    Solarwinds II: secret key boogaloo!