Originally released as part of AppSecCali 2015 Talk "Marshalling Pickles: how deserializing objects will ruin your day" with gadget chains for Apache Commons Collections (3.x and 4.x), Spring ...
The overall quant rating is not an average of the factor grades listed. Instead, it gives greater weight to the metrics with the strongest predictive value.