Flask App vulnerable to Insecure Deserialization
426
What is Insecure Deserialization?
Insecure Deserialization is a vulnerability which occurs when untrusted data is used to abuse the logic of an application, inflict a denial of service (DOS) attack, or even execute arbitrary code upon it being deserialized.
Using Python Flask and Json Pickle, a vulnerable app has been developed in an Ubuntu Container.
To access this app run the container by using the below mentioned command:
docker run -p 3000:3000 dockerbucket/insecure_deserialization
For more reference regarding Insecure Deserialization you can have a look into my blog where things are explained in detail. Link for the blog has been provided below
https://medium.com/@0xbughunter/de-serialization-sometimes-pickle-can-be-too-sour-45c930e18b8e
Content type
Image
Digest
Size
180.5 MB
Last updated
almost 8 years ago
docker pull dockerbucket/insecure_deserialization