Описание
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
| Релиз | Статус | Примечание |
|---|---|---|
| devel | DNE | |
| esm-apps-legacy/xenial | needs-triage | |
| esm-apps/bionic | needs-triage | |
| esm-apps/xenial | ignored | end of ESM support, was needs-triage |
| jammy | DNE | |
| noble | DNE | |
| plucky | DNE | |
| questing | DNE | |
| resolute | DNE | |
| upstream | needs-triage |
Показывать по
10
Ссылки на источники
9.8 Critical
CVSS3
Связанные уязвимости
CVSS3: 9.8
nvd
12 месяцев назад
A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library
CVSS3: 9.8
debian
12 месяцев назад
A Java deserialisation vulnerability has been discovered in Jaspersoft ...
CVSS3: 9.8
github
12 месяцев назад
JasperReports has a Java deserialisation vulnerability
9.8 Critical
CVSS3