CVE-2022-1415

CVE-2022-1415

A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

Source: CVE-2022-1415

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다