Описание
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.
Пакеты
Пакет | Статус | Версия исправления | Релиз | Тип |
---|---|---|---|---|
clojure | fixed | 1.9.0-1 | package |
Примечания
https://github.com/clojure/clojure/commit/271674c9b484d798484d134a5ac40a6df15d3ac3 (clojure-1.9.0-alpha20)
EPSS
Связанные уязвимости
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.
Clojure classes can be used to craft a serialized object that runs arbitrary code on deserialization
Уязвимость интерпретатора языка программирования Clojure, связанная с десериализацией ненадежных данных, позволяющая нарушителю выполнить произвольный код
EPSS