Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hjgm-f7vx-m5g7

Опубликовано: 06 янв. 2022
Источник: github
Github: Прошло ревью
CVSS3: 9.8

Описание

Deserialization of Untrusted Data in Apache Heron

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).

Пакеты

Наименование

org.apache.heron:heron-simulator

maven
Затронутые версииВерсия исправления

>= 0.20.0-incubating, <= 0.20.2-incubating

0.20.3-incubating

EPSS

Процентиль: 93%
0.09859
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9.8
nvd
почти 6 лет назад

It was noticed that Apache Heron 0.20.2-incubating, Release 0.20.1-incubating, and Release v-0.20.0-incubating does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerabilities (CWE-502: Deserialization of Untrusted Data).

EPSS

Процентиль: 93%
0.09859
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-502