VYPR

Scala Collection Compat

by Scala Lang

CVEs (1)

  • CVE-2022-36944CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.09

    Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary…