PT-2018-16201 · Cryo · Cryo
Greendog
·
Published
2018-08-17
·
Updated
2020-09-18
·
CVE-2018-3784
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
cryo version 0.0.6
cryo (all versions)
Description
A code injection issue in cryo allows an attacker to execute arbitrary code due to an insecure implementation of deserialization. This affects all versions of cryo.
Recommendations
For cryo version 0.0.6, at the moment, there is no information about a newer version that contains a fix for this issue.
For all versions of cryo, consider using an alternative module until a fix is made available. As a temporary workaround, consider restricting the use of the deserialization function to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cryo