VYPR

Jython

by Jython Project

Source repositories

CVEs (2)

  • CVE-2016-4000CriJul 6, 2017
    risk 0.64cvss 9.8epss 0.07

    Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.

  • CVE-2013-2027Feb 13, 2015
    risk 0.00cvss epss 0.00

    Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.