JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://github.com/java-decompiler/jd-gui/issues/415 | issue tracking exploit |
https://github.com/java-decompiler/jd-gui/pull/417 | issue tracking exploit |