Описание
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel for Spring Boot 3 | drools-core | Not affected | ||
| Red Hat build of Quarkus | drools-core | Not affected | ||
| Red Hat Decision Manager 7 | drools-core | Affected | ||
| Red Hat Fuse 7 | drools-core | Not affected | ||
| Red Hat Integration Camel K 1 | drools-core | Not affected | ||
| Red Hat Integration Camel Quarkus 1 | drools-core | Not affected | ||
| Red Hat JBoss Data Grid 7 | drools-core | Not affected | ||
| Red Hat JBoss Data Virtualization 6 | drools-core | Not affected | ||
| Red Hat JBoss Enterprise Application Platform 6 | drools-core | Out of support scope | ||
| Red Hat JBoss Enterprise Application Platform 7 | drools-core | Not affected |
Показывать по
Дополнительная информация
Статус:
EPSS
8.8 High
CVSS3
Связанные уязвимости
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Drools Core Deserialization of Untrusted Data vulnerability
Уязвимость системы управления бизнес-правилами Drools, связана с восстановлением в памяти недостоверных данных, позволяющая нарушителю выполнить произвольный код
EPSS
8.8 High
CVSS3