CWE-502
Deserialization of Untrusted Data
Description
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-586
CVEs mapped to this weakness (3,308)
page 164 of 166| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-39311 | Cri | 0.00 | 9.1 | 0.02 | Oct 14, 2022 | GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The… | ||
| CVE-2022-40314 | Cri | 0.00 | 9.8 | 0.02 | Sep 30, 2022 | A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified. | ||
| CVE-2022-36038 | Hig | 0.00 | 8.8 | 0.01 | Sep 6, 2022 | CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to… | ||
| CVE-2022-2433 | Hig | 0.00 | 7.5 | 0.02 | Sep 6, 2022 | The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR… | ||
| CVE-2021-4125 | Hig | 0.00 | 8.1 | 0.01 | Aug 24, 2022 | It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift… | ||
| CVE-2022-25863 | Hig | 0.00 | 8.1 | 0.02 | Jun 10, 2022 | The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this… | ||
| CVE-2022-27158 | Cri | 0.00 | 9.8 | 0.01 | Apr 15, 2022 | pearweb < 1.32 suffers from Deserialization of Untrusted Data. | ||
| CVE-2022-1032 | Hig | 0.00 | 7.2 | 0.02 | Mar 29, 2022 | Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6. | ||
| CVE-2021-41110 | Cri | 0.00 | 9.1 | 0.03 | Oct 1, 2021 | cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no… | ||
| CVE-2021-36163 | Cri | 0.00 | 9.8 | 0.03 | Sep 7, 2021 | In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and… | ||
| CVE-2021-32568 | Hig | 0.00 | 7.8 | 0.01 | Sep 6, 2021 | mrdoc is vulnerable to Deserialization of Untrusted Data | ||
| CVE-2021-33806 | Cri | 0.00 | 9.8 | 0.03 | Jun 3, 2021 | The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization. | ||
| CVE-2021-32634 | Hig | 0.00 | 7.2 | 0.01 | May 21, 2021 | Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a92… | ||
| CVE-2020-7385 | Hig | 0.00 | 8.1 | 0.02 | Apr 23, 2021 | By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework… | ||
| CVE-2021-23338 | Med | 0.00 | 6.6 | 0.04 | Feb 15, 2021 | This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function. | ||
| CVE-2021-27213 | Cri | 0.00 | 9.8 | 0.03 | Feb 14, 2021 | config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used. | ||
| CVE-2021-21249 | Cri | 0.00 | 9.6 | 0.03 | Jan 15, 2021 | OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (when not using… | ||
| CVE-2020-26207 | Hig | 0.00 | 8.0 | 0.02 | Nov 4, 2020 | DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened. | ||
| CVE-2020-26945 | Hig | 0.00 | 8.1 | 0.02 | Oct 10, 2020 | MyBatis before 3.5.6 mishandles deserialization of object streams. | ||
| CVE-2020-15188 | Cri | 0.00 | 10.0 | 0.05 | Sep 18, 2020 | SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any… |
- risk 0.00cvss 9.1epss 0.02
GoCD is a continuous delivery server. GoCD helps you automate and streamline the build-test-release cycle for continuous delivery of your product. GoCD versions prior to 21.1.0 are vulnerable to remote code execution on the server from a malicious or compromised agent. The…
- risk 0.00cvss 9.8epss 0.02
A remote code execution risk when restoring backup files originating from Moodle 1.9 was identified.
- risk 0.00cvss 8.8epss 0.01
CircuitVerse is an open-source platform which allows users to construct digital logic circuits online. A remote code execution (RCE) vulnerability in CircuitVerse allows authenticated attackers to execute arbitrary code via specially crafted JSON payloads. This issue may lead to…
- risk 0.00cvss 7.5epss 0.02
The WordPress Infinite Scroll – Ajax Load More plugin for WordPress is vulnerable to deserialization of untrusted input via the 'alm_repeaters_export' parameter in versions up to, and including 5.5.3. This makes it possible for unauthenticated users to call files using a PHAR…
- risk 0.00cvss 8.1epss 0.01
It was found that the original fix for log4j CVE-2021-44228 and CVE-2021-45046 in the OpenShift metering hive containers was incomplete, as not all JndiLookup.class files were removed. This CVE only applies to the OpenShift Metering hive container images, shipped in OpenShift…
- risk 0.00cvss 8.1epss 0.02
The package gatsby-plugin-mdx before 2.14.1, from 3.0.0 and before 3.15.2 are vulnerable to Deserialization of Untrusted Data when passing input through to the gray-matter package, due to its default configurations that are missing input sanitization. Exploiting this…
- risk 0.00cvss 9.8epss 0.01
pearweb < 1.32 suffers from Deserialization of Untrusted Data.
- risk 0.00cvss 7.2epss 0.02
Insecure deserialization of not validated module file in GitHub repository crater-invoice/crater prior to 6.0.6.
- risk 0.00cvss 9.1epss 0.03
cwlviewer is a web application to view and share Common Workflow Language workflows. Versions prior to 1.3.1 contain a Deserialization of Untrusted Data vulnerability. Commit number f6066f09edb70033a2ce80200e9fa9e70a5c29de (dated 2021-09-30) contains a patch. There are no…
- risk 0.00cvss 9.8epss 0.03
In Apache Dubbo, users may choose to use the Hessian protocol. The Hessian protocol is implemented on top of HTTP and passes the body of a POST request directly to a HessianSkeleton: New HessianSkeleton are created without any configuration of the serialization factory and…
- risk 0.00cvss 7.8epss 0.01
mrdoc is vulnerable to Deserialization of Untrusted Data
- risk 0.00cvss 9.8epss 0.03
The BDew BdLib library before 1.16.1.7 for Minecraft allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of its use of Java serialization.
- risk 0.00cvss 7.2epss 0.01
Emissary is a distributed, peer-to-peer, data-driven workflow framework. Emissary 6.4.0 is vulnerable to Unsafe Deserialization of post-authenticated requests to the [`WorkSpaceClientEnqueue.action`](https://github.com/NationalSecurityAgency/emissary/blob/30c54ef16c6eb6ed09604a92…
- risk 0.00cvss 8.1epss 0.02
By launching the drb_remote_codeexec exploit, a Metasploit Framework user will inadvertently expose Metasploit to the same deserialization issue that is exploited by that module, due to the reliance on the vulnerable Distributed Ruby class functions. Since Metasploit Framework…
- risk 0.00cvss 6.6epss 0.04
This affects all versions of package qlib. The workflow function in cli part of qlib was using an unsafe YAML load function.
- risk 0.00cvss 9.8epss 0.03
config.py in pystemon before 2021-02-13 allows code execution via YAML deserialization because SafeLoader and safe_load are not used.
- risk 0.00cvss 9.6epss 0.03
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is an issue involving YAML parsing which can lead to post-auth remote code execution. In order to parse and process YAML files, OneDev uses SnakeYaml which by default (when not using…
- risk 0.00cvss 8.0epss 0.02
DatabaseSchemaViewer before version 2.7.4.3 is vulnerable to arbitrary code execution if a user is tricked into opening a specially crafted `.dbschema` file. The patch was released in v2.7.4.3. As a workaround, ensure `.dbschema` files from untrusted sources are not opened.
- risk 0.00cvss 8.1epss 0.02
MyBatis before 3.5.6 mishandles deserialization of object streams.
- risk 0.00cvss 10.0epss 0.05
SOY CMS 3.0.2.327 and earlier is affected by Unauthenticated Remote Code Execution (RCE). The allows remote attackers to execute any arbitrary code when the inquiry form feature is enabled by the service. The vulnerability is caused by unserializing the form without any…