PT-2018-17481 · Facebook · Buck

Published

2018-12-31

·

Updated

2025-05-06

·

CVE-2018-6331

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buck versions prior to v2018.06.25.01
Description The issue arises from the Buck parser-cache command, which utilizes Java serialized objects to load and save state. If the state information is maliciously crafted, deserializing it could lead to code execution.
Recommendations For versions prior to v2018.06.25.01, update to version v2018.06.25.01 or later to resolve the issue.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2018-6331

Affected Products

Buck