You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
This repository has been archived by the owner on Apr 5, 2023. It is now read-only.
The SDO project is not affected because it implements its own data serialization and does not use HTTPInvokerServiceExporter or RemoteInvocationSerializingExporter.
Sign up for freeto subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Describe the bug
potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Found in ops, ocs, and rv war files.
To Reproduce
Steps to reproduce the behavior:
Aquasec security scan on spring-web-5.3.24.jar and spring-web-5.3.25.jar
Expected behavior
This vulnerability should not show up on our Aquasec scan results
Additional context
these vulnerabilities are fixed in version 6.0.0
https://nvd.nist.gov/vuln/detail/CVE-2016-1000027
The text was updated successfully, but these errors were encountered: