CVE-2017-5641 – org.apache.flex.blazeds:flex-messaging-remoting
Package
Manager: maven
Name: org.apache.flex.blazeds:flex-messaging-remoting
Vulnerable Version: >=0 <4.7.3
Severity
Level: Critical
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS: 0.37365 pctl0.97065
Details
Apache Flex BlazeDS unsafe deserialization Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One vector in the Java standard library exists that allows an attacker to trigger possibly further exploitable Java deserialization of untrusted data. Other known vectors in third party libraries can be used to trigger remote code execution.
Metadata
Created: 2022-05-13T01:02:10Z
Modified: 2023-10-06T21:06:16Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-w8v7-prhw-xjpw/GHSA-w8v7-prhw-xjpw.json
CWE IDs: ["CWE-502"]
Alternative ID: GHSA-w8v7-prhw-xjpw
Finding: F096
Auto approve: 1