VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,308)

page 164 of 166
  • CVE-2022-39311CriOct 14, 2022
    risk 0.00cvss 9.1epss 0.02

    GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…

  • CVE-2022-40314CriSep 30, 2022
    risk 0.00cvss 9.8epss 0.02

    A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.

  • CVE-2022-36038HigSep 6, 2022
    risk 0.00cvss 8.8epss 0.01

    CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to…

  • CVE-2022-2433HigSep 6, 2022
    risk 0.00cvss 7.5epss 0.02

    The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR…

  • CVE-2021-4125HigAug 24, 2022
    risk 0.00cvss 8.1epss 0.01

    It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift…

  • CVE-2022-25863HigJun 10, 2022
    risk 0.00cvss 8.1epss 0.02

    The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this…

  • CVE-2022-27158CriApr 15, 2022
    risk 0.00cvss 9.8epss 0.01

    pearweb < 1.32 suffers from Deserialization of Untrusted Data.

  • CVE-2022-1032HigMar 29, 2022
    risk 0.00cvss 7.2epss 0.02

    Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.

  • CVE-2021-41110CriOct 1, 2021
    risk 0.00cvss 9.1epss 0.03

    cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no…

  • CVE-2021-36163CriSep 7, 2021
    risk 0.00cvss 9.8epss 0.03

    In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and…

  • CVE-2021-32568HigSep 6, 2021
    risk 0.00cvss 7.8epss 0.01

    mrdoc is vulnerable to Deserialization of Untrusted Data

  • CVE-2021-33806CriJun 3, 2021
    risk 0.00cvss 9.8epss 0.03

    The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.

  • CVE-2021-32634HigMay 21, 2021
    risk 0.00cvss 7.2epss 0.01

    Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a92…

  • CVE-2020-7385HigApr 23, 2021
    risk 0.00cvss 8.1epss 0.02

    By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework…

  • CVE-2021-23338MedFeb 15, 2021
    risk 0.00cvss 6.6epss 0.04

    This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.

  • CVE-2021-27213CriFeb 14, 2021
    risk 0.00cvss 9.8epss 0.03

    config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.

  • CVE-2021-21249CriJan 15, 2021
    risk 0.00cvss 9.6epss 0.03

    OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (when not using…

  • CVE-2020-26207HigNov 4, 2020
    risk 0.00cvss 8.0epss 0.02

    DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.

  • CVE-2020-26945HigOct 10, 2020
    risk 0.00cvss 8.1epss 0.02

    MyBatis before 3.5.6 mishandles deserialization of object streams.

  • CVE-2020-15188CriSep 18, 2020
    risk 0.00cvss 10.0epss 0.05

    SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any…