ZeroHour

CVE-2024-28212

CVSS 3.1
9.8 critical
EPSS
1%p61
Published
()
Modified
Description

nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.

Vendors
naver
Products
ngrinder
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.