Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhvc-rf83-29wq

Опубликовано: 27 янв. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 10

Описание

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java.

This issue affects tis: before v4.3.0.

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java.

This issue affects tis: before v4.3.0.

EPSS

Процентиль: 17%
0.00053
Низкий

10 Critical

CVSS4

Дефекты

CWE-434

Связанные уязвимости

nvd
12 дней назад

Unrestricted Upload of File with Dangerous Type, Deserialization of Untrusted Data vulnerability in datavane tis (tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules). This vulnerability is associated with program files XmlFile.Java. This issue affects tis: before v4.3.0.

EPSS

Процентиль: 17%
0.00053
Низкий

10 Critical

CVSS4

Дефекты

CWE-434