[PATCH] Address ZDI-20-1051 / ZDI-CAN-10436: Prevent deserializing a class.
Also guard against some other possibly unwanted deserialisations. It is debatable if this constitutes an actual attack vector before the change. However, the change rules out any such possibility.