nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
History

Thu, 22 Aug 2024 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: naver

Published: 2024-03-07T04:49:47.237Z

Updated: 2024-08-22T20:01:34.318Z

Reserved: 2024-03-07T02:38:58.221Z

Link: CVE-2024-28213

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:49.537Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-03-07T05:15:54.710

Modified: 2024-08-22T20:35:07.957

Link: CVE-2024-28213

cve-icon Redhat

No data.