Lucene search

K

Scala Security Vulnerabilities

cve
cve

CVE-2017-15288

The compilation daemon in Scala before 2.10.7, 2.11.x before 2.11.12, and 2.12.x before 2.12.4 uses weak permissions for private files in /tmp/scala-devel/${USER:shared}/scalac-compile-server-port, which allows local users to write to arbitrary class files and consequently gain privileges.

7.8CVSS

7.5AI Score

0.0004EPSS

2017-11-15 04:29 PM
61
2
cve
cve

CVE-2022-36944

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network con...

9.8CVSS

9.4AI Score

0.008EPSS

2022-09-23 06:15 PM
101
9