PT-2016-3147 · Jython · Jython

Publicado

2016-01-19

·

Atualizado

2022-05-13

·

CVE-2016-4000

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jython versions prior to 2.7.1rc1
Description The issue is related to the restoration of untrusted data in memory, which can be exploited by a remote attacker to execute arbitrary code using a specially crafted serialized PyFunction object. This can potentially allow the execution of arbitrary code.
Recommendations For versions prior to 2.7.1rc1, update to version 2.7.1rc1 or later to resolve the issue. As a temporary workaround, consider restricting the use of serialized PyFunction objects until a patch is available.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-01747
CVE-2016-4000
DLA-989-1
DSA-3893-1
GHSA-6R7R-JJ8H-PQ6V
SNYK-JAVA-ORGPYTHON-31451

Produtos afetados

Jython