Impact
A deserialization flaw exists in the Kryo Injection component of the OBP-API, specifically the KryoInjection.invert method within Redis.scala. The vulnerability allows an attacker to externally supply crafted data that is processed by the deserialization routine, potentially leading to unintended effects or corruption of cached content. The flaw carries a CVSS score of 2.1, indicating a low innate severity from a purely technical standpoint, yet the exposure to malicious payloads introduces a notable risk in the context of untrusted input handling.
Affected Systems
OpenBankProject’s OBP-API, versions up to and including 1.10.1. The vulnerability resides in the Kryo Handler component, with the KryoInjection.invert method of the Redis module being the attack surface. Users running any version of the API prior to the latest patch are exposed to this flaw.
Risk and Exploitability
The attack can be launched remotely and requires a high level of complexity; exploitation is described as difficult. The EPSS score is below 1% and the issue is not listed in CISA’s KEV catalog, which together indicate a low probability of widespread abuse. Nonetheless, because the flaw permits deserialization of externally supplied data, a sufficiently skilled adversary with network access to the API could craft malicious input. This could lead to undesired behavior such as corruption of cached data or other impact tied to the logic that handles deserialized objects. The low CVSS base combined with the high complexity of exploitation limits the likelihood of widespread attacks but does not eliminate the need for mitigation.
OpenCVE Enrichment