VYPR

Scala

by Scala Lang

Source repositories

CVEs (2)

  • CVE-2022-36944CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.09

    Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary…

  • CVE-2017-15288HigNov 15, 2017
    risk 0.51cvss 7.8epss 0.00

    The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain…