[MAVEN:GHSA-M5Q8-58WH-XXQ4] Drools Core Deserialization of Untrusted Data vulnerability

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

Package Affected Version
pkg:maven/org.drools/drools-core < 7.69.0.Final
Package Fixed Version
pkg:maven/org.drools/drools-core = 7.69.0.Final
ID
MAVEN:GHSA-M5Q8-58WH-XXQ4
Severity
moderate
URL
https://github.com/advisories/GHSA-m5q8-58wh-xxq4
Published
2023-09-11T21:30:17
(12 months ago)
Modified
2023-11-05T05:01:16
(10 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.drools/drools-core org.drools drools-core < 7.69.0.Final
Fixed pkg:maven/org.drools/drools-core org.drools drools-core = 7.69.0.Final
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...