CVE-2024-28213
—CVSS 3.1
9.8 critical
EPSS
1%p66
Published
()
Modified
Description
nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
- Vendors
- naver
- Products
- ngrinder
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.