PT-2024-6048 · Clojure+1 · Clojure+1

Published

2024-01-22

·

Updated

2024-09-04

·

CVE-2017-20189

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Clojure versions prior to 1.9.0
Description The issue is related to the deserialization of untrusted data in the Clojure programming language interpreter. It allows a remote attacker to execute arbitrary code upon deserialization. This is particularly relevant in scenarios where a server deserializes objects from untrusted sources.
Recommendations For versions prior to 1.9.0, update to version 1.9.0 or later to resolve the issue. As a temporary workaround, consider restricting the deserialization of untrusted objects to minimize the risk of exploitation.

Exploit

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2024-06870
CVE-2017-20189
GHSA-JGXC-8MWQ-9XQW

Affected Products

Clojure
Red Os