Lucene search

K
osvGoogleOSV:GHSA-GJ76-429M-56WC
HistoryFeb 04, 2020 - 10:38 p.m.

Deserialization of Untrusted Data in Apache Olingo

2020-02-0422:38:22
Google
osv.dev
12

0.006 Low

EPSS

Percentile

78.1%

Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn’t check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker’s code in the worse case.

0.006 Low

EPSS

Percentile

78.1%

Related for OSV:GHSA-GJ76-429M-56WC