VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 153 of 156
  • CVE-2024-47074CriOct 11, 2024
    risk 0.00cvss 9.8epss 0.01

    DataEase is an open source data visualization analysis tool. In Dataease, the PostgreSQL data source in the data source function can customize the JDBC connection parameters and the PG server target to be connected. In backend/src/main/java/io/dataease/provider/datasource/JdbcPro…

  • CVE-2024-42362HigAug 20, 2024
    risk 0.00cvss 8.8epss 0.01

    Hertzbeat is an open source, real-time monitoring system. Hertzbeat has an authenticated (user role) RCE via unsafe deserialization in /api/monitors/import. This vulnerability is fixed in 1.6.0.

  • CVE-2024-8003LowAug 20, 2024
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Go-Tribe gotribe-admin 1.0 and classified as problematic. Affected by this issue is the function InitRoutes of the file internal/app/routes/routes.go of the component Log Handler. The manipulation leads to deserialization. The patch is identified as…

  • CVE-2024-7067MedJul 24, 2024
    risk 0.00cvss 6.3epss 0.01

    A vulnerability was found in kirilkirkov Ecommerce-Laravel-Bootstrap up to 1f1097a3448ce8ec53e034ea0f70b8e2a0e64a87. It has been rated as critical. Affected by this issue is the function getCartProductsIds of the file app/Cart.php. The manipulation of the argument laraCart leads…

  • CVE-2024-31224CriApr 8, 2024
    risk 0.00cvss 9.8epss 0.01

    GPT Academic provides interactive interfaces for large language models. A vulnerability was found in gpt_academic versions 3.64 through 3.73. The server deserializes untrustworthy data from the client, which may risk remote code execution. Any device that exposes the GPT…

  • CVE-2024-28861CriMar 22, 2024
    risk 0.00cvss 9.8epss 0.02

    Symfony 1 is a community-driven fork of the 1.x branch of Symfony, a PHP framework for web projects. Starting in version 1.1.0 and prior to version 1.5.19, Symfony 1 has a gadget chain due to dangerous deserialization in `sfNamespacedParameterHolder` class that would enable an…

  • CVE-2024-23328CriFeb 29, 2024
    risk 0.00cvss 9.1epss 0.01

    Dataease is an open source data visualization analysis tool. A deserialization vulnerability exists in the DataEase datasource, which can be exploited to execute arbitrary code. The location of the vulnerability code is `core/core-backend/src/main/java/io/dataease/datasource/type…

  • CVE-2023-51389CriFeb 22, 2024
    risk 0.00cvss 9.8epss 0.01

    Hertzbeat is a real-time monitoring system. At the interface of `/define/yml`, SnakeYAML is used as a parser to parse yml content, but no security configuration is used, resulting in a YAML deserialization vulnerability. Version 1.4.1 fixes this vulnerability.

  • CVE-2023-51700MedDec 27, 2023
    risk 0.00cvss 6.4epss 0.01

    Unofficial Mobile BankID Integration for WordPress lets users employ Mobile BankID to authenticate themselves on your WordPress site. Prior to 1.0.1, WP-Mobile-BankID-Integration is affected by a vulnerability classified as a Deserialization of Untrusted Data vulnerability,…

  • CVE-2023-44392HigOct 9, 2023
    risk 0.00cvss 8.2epss 0.01

    Garden provides automation for Kubernetes development and testing. Prior tov ersions 0.13.17 and 0.12.65, Garden has a dependency on the cryo library, which is vulnerable to code injection due to an insecure implementation of deserialization. Garden stores serialized objects…

  • CVE-2023-38689HigAug 4, 2023
    risk 0.00cvss 8.1epss 0.01

    Logistics Pipes is a modification (a.k.a. mod) for the computer game Minecraft Java Edition. The mod used Java's `ObjectInputStream#readObject` on untrusted data coming from clients or servers over the network resulting in possible remote code execution when sending specifically…

  • CVE-2023-29006HigApr 5, 2023
    risk 0.00cvss 8.8epss 0.01

    The Order GLPI plugin allows users to manage order management within GLPI. Starting with version 1.8.0 and prior to versions 2.7.7 and 2.10.1, an authenticated user that has access to standard interface can craft an URL that can be used to execute a system command. Versions…

  • CVE-2023-26234MedFeb 21, 2023
    risk 0.00cvss 6.6epss 0.01

    JD-GUI 1.6.6 allows deserialization via UIMainWindowPreferencesProvider.singleInstance.

  • CVE-2023-25558HigFeb 11, 2023
    risk 0.00cvss 7.5epss 0.01

    DataHub is an open-source metadata platform. When the DataHub frontend is configured to authenticate via SSO, it will leverage the pac4j library. The processing of the `id_token` is done in an unsafe manner which is not properly accounted for by the DataHub frontend.…

  • CVE-2022-4890MedJan 16, 2023
    risk 0.00cvss 6.3epss 0.01

    A vulnerability, which was classified as critical, has been found in abhilash1985 PredictApp. This issue affects some unknown processing of the file config/initializers/new_framework_defaults_7_0.rb of the component Cookie Handler. The manipulation leads to deserialization. The…

  • CVE-2022-41958HigNov 25, 2022
    risk 0.00cvss 7.3epss 0.00

    super-xray is a web vulnerability scanning tool. Versions prior to 0.7 assumed trusted input for the program config which is stored in a yaml file. An attacker with local access to the file could exploit this and compromise the program. This issue has been addressed in commit…

  • CVE-2022-39311CriOct 14, 2022
    risk 0.00cvss 9.1epss 0.02

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-36038HigSep 6, 2022
    risk 0.00cvss 8.8epss 0.01

    CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to…

  • CVE-2022-2433HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.01

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR…