Hacker News new | ask | show | jobs
by berdario 4472 days ago
How can a JRuby (or Clojure, or Jython...) REST api trigger a vulnerability in the Java reflection?

I was always under the impression that such kind of vulnerabilities were only a problem for Java applets (where the sandbox is actually important)

Has any exploit ever been built for such circumstances? (I admit that I'm ignorant of their existance)