QID 994945
Date Published: 2023-08-22
QID 994945: Java (Maven) Security Update for org.graniteds:granite-core (GHSA-8m35-r25c-qr56)
The Java implementation of GraniteDS, version 3.1.1.GA, AMF3 deserializers derives class instances from java.io.Externalizable rather than the AMF3 specification's recommendation of flash.utils.IExternalizable. A remote attacker with the ability to spoof or control an RMI server connection may be able to send serialized Java objects that execute arbitrary code when deserialized.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-8m35-r25c-qr56 for updates and patch information.
Vendor References
- GHSA-8m35-r25c-qr56 -
github.com/advisories/GHSA-8m35-r25c-qr56
CVEs related to QID 994945
Software Advisories
| Advisory ID | Software | Component | Link |
|---|