java.lang.ClassLoader
class.
While often benign, any instantiations of ClassLoader
should be closely examined in any security audit.
Example:
Class<?> loadExtraClass(String name) throws Exception {
try(URLClassLoader loader =
new URLClassLoader(new URL[]{new URL("extraClasses/")})) {
return loader.loadClass(name);
}
}