Skip to content

Deserialization Gadget Scan

deserialization-gadget-scan is a critical severity check in the web category, written in java. Its source is templates/web/deserialization/DeserializationGadgetScan.java in cert-x-gen-templates.

Detects Java deserialization attack surfaces by probing TCP services for Java serialization magic bytes, fingerprinting exposed gadget chain libraries (CommonsCollections, Spring Beans, Groovy, etc.) via class descriptor leakage and exception analysis. Does NOT send exploit payloads.

Field Value
Id deserialization-gadget-scan
Severity critical
Language java
Category web
Author CERT-X-GEN Security Team
Template version not recorded
Confidence 90
CVSS not recorded
Weakness CWE-502
Tags java, deserialization, ysoserial, gadget-chain, rce, commons-collections, jmx, rmi, jboss
Target kind not recorded
Oracle not recorded

Declared in the header. cxg parses @references and then discards it, and nothing at scan time reads it, so this is the only place the links a template cites are surfaced.

To see what the copy on your machine says about itself, and to confirm it is installed at all:

Terminal window
cxg template info deserialization-gadget-scan

The id it prints is the one to pass anywhere a template is selected. See cxg template for the rest of the subcommand, Scan a target for running a scan, and A match is not a finding for how to read what comes back.