VYPR

CWE-502

Deserialization of Untrusted Data

BaseDraftLikelihood: Medium

Description

The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-586

CVEs mapped to this weakness (3,323)

page 79 of 167
  • CVE-2020-9301HigDec 11, 2020
    risk 0.57cvss 8.8epss 0.02

    Nolan Ray from Apple Information Security identified a security vulnerability in Spinnaker, all versions prior to version 1.23.4, 1.22.4 or 1.21.5. The vulnerability exists within the handling of SpEL expressions that allows an attacker to read and write arbitrary files within…

  • CVE-2020-15172HigSep 15, 2020
    risk 0.57cvss 8.7epss 0.02

    The Act module for Red Discord Bot before commit 6b9f3b86 is vulnerable to Remote Code Execution. With this exploit, Discord users can use specially crafted messages to perform destructive actions and/or access sensitive information. Unloading the Act module with `unload act`…

  • CVE-2020-15148HigSep 15, 2020
    risk 0.57cvss 8.9epss 0.78

    Yii 2 (yiisoft/yii2) before version 2.0.38 is vulnerable to remote code execution if the application calls `unserialize()` on arbitrary user input. This is fixed in version 2.0.38. A possible workaround without upgrading is available in the linked advisory.

  • CVE-2020-24034HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.04

    Sagemcom F@ST 5280 routers using firmware version 1.150.61 have insecure deserialization that allows any authenticated user to perform a privilege escalation to any other user. By making a request with valid sess_id, nonce, and ha1 values inside of the serialized session cookie,…

  • CVE-2020-17405HigSep 1, 2020
    risk 0.57cvss 8.8epss 0.02

    This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the…

  • CVE-2020-10289HigAug 20, 2020
    risk 0.57cvss 8.8epss 0.02

    Use of unsafe yaml load. Allows instantiation of arbitrary objects. The flaw itself is caused by an unsafe parsing of YAML values which happens whenever an action message is processed to be sent, and allows for the creation of Python objects. Through this flaw in the ROS core…

  • CVE-2020-5413CriJul 31, 2020
    risk 0.57cvss 9.8epss 0.04

    Spring Integration framework provides Kryo Codec implementations as an alternative for Java (de)serialization. When Kryo is configured with default options, all unregistered classes are resolved on demand. This leads to the "deserialization gadgets" exploit when provided data…

  • CVE-2020-15086CriJul 29, 2020
    risk 0.57cvss 9.8epss 0.04

    In TYPO3 installations with the "mediace" extension from version 7.6.2 and before version 7.6.5, it has been discovered that an internal verification mechanism can be used to generate arbitrary checksums. The allows to inject arbitrary data having a valid cryptographic message…

  • CVE-2020-2211HigJul 2, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins ElasticBox Jenkins Kubernetes CI/CD Plugin 1.3 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2020-14933HigJun 20, 2020
    risk 0.57cvss 8.8epss 0.01

    compose.php in SquirrelMail 1.4.22 calls unserialize for the $attachments value, which originates from an HTTP POST request. NOTE: the vendor disputes this because these two conditions for PHP object injection are not satisfied: existence of a PHP magic method (such as __wakeup…

  • CVE-2018-21234CriMay 21, 2020
    risk 0.57cvss 9.8epss 0.08

    Jodd before 5.0.4 performs Deserialization of Untrusted JSON Data when setClassMetadataName is set.

  • CVE-2020-11067HigMay 14, 2020
    risk 0.57cvss 8.8epss 0.02

    In TYPO3 CMS 9.0.0 through 9.5.16 and 10.0.0 through 10.4.1, it has been discovered that backend user settings (in $BE_USER->uc) are vulnerable to insecure deserialization. In combination with vulnerabilities of third party components, this can lead to remote code execution. A…

  • CVE-2020-4272HigApr 15, 2020
    risk 0.57cvss 8.8epss 0.03

    IBM QRadar 7.3.0 to 7.3.3 Patch 2 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted request specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable server.…

  • CVE-2020-6219HigApr 14, 2020
    risk 0.57cvss 8.8epss 0.01

    SAP Business Objects Business Intelligence Platform (CrystalReports WebForm Viewer), versions 4.1, 4.2, and Crystal Reports for VS version 2010, allows an attacker with basic authorization to perform deserialization attack in the application, leading to service interruptions and…

  • CVE-2020-7610CriMar 30, 2020
    risk 0.57cvss 9.8epss 0.02

    All versions of bson before 1.1.4 are vulnerable to Deserialization of Untrusted Data. The package will ignore an unknown value for an object's _bsotype, leading to cases where an object is serialized as a document rather than the intended BSON type.

  • CVE-2020-2168HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins Azure Container Service Plugin 1.0.1 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2020-2167HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins OpenShift Pipeline Plugin 1.0.56 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2020-2166HigMar 25, 2020
    risk 0.57cvss 8.8epss 0.02

    Jenkins Pipeline: AWS Steps Plugin 1.40 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.

  • CVE-2016-1487HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.03

    Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.

  • CVE-2020-2158HigMar 9, 2020
    risk 0.57cvss 8.8epss 0.03

    Jenkins Literate Plugin 1.0 and earlier does not configure its YAML parser to prevent the instantiation of arbitrary types, resulting in a remote code execution vulnerability.