QID 998093
QID 998093: Java (Maven) Security Update for io.fabric8:fabric8-maven-plugin (GHSA-w7gj-h6f2-x4c6)
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-w7gj-h6f2-x4c6 for updates and patch information.
Vendor References
- GHSA-w7gj-h6f2-x4c6 -
github.com/advisories/GHSA-w7gj-h6f2-x4c6
CVEs related to QID 998093
Software Advisories
| Advisory ID | Software | Component | Link |
|---|