Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:20677
HistoryJul 08, 2019 - 8:47 a.m.

Remote Code Execution

2019-07-0808:47:15
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
4

0.003 Low

EPSS

Percentile

70.0%

Pippo is vulnerable to remote code execution attacks. A remote, unauthenticated attacker could create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie to exploit the flawed Cookie Handler component causing denial of service conditions. Affected by this issue is the function SerializationSessionDataTranscoder.decode().

CPENameOperatorVersion
pippo sessionle1.11.0
pippo sessionle1.11.0

0.003 Low

EPSS

Percentile

70.0%

Related for VERACODE:20677