Lucene search

K
osvGoogleOSV:GHSA-VRMW-2XHQ-HRMP
HistoryMay 24, 2022 - 5:21 p.m.

Wildfly Unsafe Deserialization Vulnerability

2022-05-2417:21:23
Google
osv.dev
17
wildfly
remote deserialization
vulnerability
enterprise application beans
lack of validation

EPSS

0.005

Percentile

75.3%

A vulnerability was found in Wildfly in versions before 20.0.0.Final, where a remote deserialization attack is possible in the Enterprise Application Beans(EJB) due to lack of validation/filtering capabilities in wildfly.