VYPR
Critical severity9.8NVD Advisory· Published Dec 31, 2018· Updated Jun 17, 2026

CVE-2018-6331

CVE-2018-6331

Description

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Facebook/Buck3 versions
    cpe:2.3:a:facebook:buck:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:facebook:buck:*:*:*:*:*:*:*:*range: <2018.06.25.01
    • (no CPE)range: <2018.06.25.01
    • (no CPE)range: v2018.06.25.01

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.