Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5gm-fgfx-hr7h

Опубликовано: 10 фев. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.8

Описание

Gadget chain attack in Nippy

A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.

Пакеты

Наименование

com.taoensso:nippy

maven
Затронутые версииВерсия исправления

< 2.14.2

2.14.2

EPSS

Процентиль: 34%
0.00141
Низкий

7.8 High

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 7.8
nvd
больше 5 лет назад

A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.

EPSS

Процентиль: 34%
0.00141
Низкий

7.8 High

CVSS3

Дефекты

CWE-502