FeatherCast

The Voice of the Apache Software Foundation

https://feathercast.apache.org

subscribe
share






ApacheCon Seville 2016 – Object Lessons: Deserialization After Apache Commons Collections – Tim Jarrett


Object Lessons: Deserialization After Apache Commons Collections – Tim Jarrett

https://feathercastapache.files.wordpress.com/2017/01/friday_001_jarrett.mp3

ItÛªs the biggest vulnerability of 2015 that didnÛªt get a brand name. The deserialization vulnerability in the Apache Commons Collections library also impacted the build server that powers most software developers and a half dozen other key pieces of the shared Java software infrastructure. But Java deserialization vulnerabilities are more widespread than you might guess.

This presentation reviews data from over 200,000 application security scans to help defenders better understand the risk of Java deserialization vulnerabilities. We look at vulnerability prevalence both overall and by industry vertical and the probability that your application has a similar vulnerability (hint: higher than youÛªd think). WeÛªll also look at real world guidance for setting security policies and coordinating with developers to get issues fixed across large numbers of applications.

More about this session



fyyd: Podcast Search Engine
share








 March 15, 2017  44m