VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,104)

page 154 of 156
  • CVE-2021-4125HigAug 24, 2022
    risk 0.00cvss 8.1epss 0.01

    It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift…

  • CVE-2022-25863HigJun 10, 2022
    risk 0.00cvss 8.1epss 0.02

    The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this…

  • CVE-2022-27158CriApr 15, 2022
    risk 0.00cvss 9.8epss 0.01

    pearweb < 1.32 suffers from Deserialization of Untrusted Data.

  • CVE-2022-1032HigMar 29, 2022
    risk 0.00cvss 7.2epss 0.02

    Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2021-41110CriOct 1, 2021
    risk 0.00cvss 9.1epss 0.03

    cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no…

  • CVE-2021-36163CriSep 7, 2021
    risk 0.00cvss 9.8epss 0.03

    In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and…

  • CVE-2021-32568HigSep 6, 2021
    risk 0.00cvss 7.8epss 0.01

    mrdoc is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-33806CriJun 3, 2021
    risk 0.00cvss 9.8epss 0.03

    The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.

  • CVE-2021-32634HigMay 21, 2021
    risk 0.00cvss 7.2epss 0.01

    Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a92…

  • CVE-2020-7385HigApr 23, 2021
    risk 0.00cvss 8.1epss 0.02

    By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework…

  • CVE-2021-23338MedFeb 15, 2021
    risk 0.00cvss 6.6epss 0.04

    This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

  • CVE-2021-27213CriFeb 14, 2021
    risk 0.00cvss 9.8epss 0.03

    config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.

  • CVE-2021-21249CriJan 15, 2021
    risk 0.00cvss 9.6epss 0.03

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (when not using…

  • CVE-2020-26207HigNov 4, 2020
    risk 0.00cvss 8.0epss 0.02

    DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

  • CVE-2020-26945HigOct 10, 2020
    risk 0.00cvss 8.1epss 0.02

    MyBatis before 3.5.6 mishandles deserialization of object streams.

  • CVE-2020-15188CriSep 18, 2020
    risk 0.00cvss 10.0epss 0.05

    SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any…

  • CVE-2020-15172HigSep 15, 2020
    risk 0.00cvss 8.7epss 0.02

    The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Discord users can use specially crafted messages to perform destructive actions and/or access sensitive information. Unloading the Act module with `unload act`…

  • CVE-2020-10289HigAug 20, 2020
    risk 0.00cvss 8.8epss 0.02

    Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core…

  • CVE-2020-14000CriJul 16, 2020
    risk 0.00cvss 9.8epss 0.03

    MIT Lifelong Kindergarten Scratch scratch-vm before 0.2.0-prerelease.20200714185213 loads extension URLs from untrusted project.json files with certain _ characters, resulting in remote code execution because the URL's content is treated as a script and is executed as a worker.…

  • CVE-2019-14466MedDec 31, 2019
    risk 0.00cvss 6.5epss 0.01

    The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize…