CVE-2022-36944

CVE-2022-36944

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with LazyList object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

Source: CVE-2022-36944

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다