CVE-2020-24164
CVSS v3.1
7.8 (High)
CVSS v2.0
6.8 (Medium)
EPSS
0.06 % (28th)
Affected Products
1
Advisories
1
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.
Weaknesses
- CWE-502
- Deserialization of Untrusted Data
- CVE Status
- PUBLISHED
- CNA
- MITRE
- Published Date
-
2020-09-11 06:15:11
(4 years ago) - Updated Date
-
2020-09-15 14:38:40
(4 years ago)
Affected Products
Loading...
Loading...
Loading...
Configuration #1
|
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...