Skip to content

Block more classes from polymorphic deserialization (CVE-2018-14718 - CVE-2018-14721) #2097

@cowtowncoder

Description

@cowtowncoder

This issue covers following CVEs related to polymorphic deserialization, gadgets:

Original vulnerability discoverer:
吴桂雄 Wuguixiong


Fixed in:

  • 2.9.7 and later
  • 2.8.11.3
  • 2.7.9.5
  • 2.6.7.3

Metadata

Metadata

Assignees

No one assigned

    Labels

    CVEIssues related to public CVEs (security vuln reports)

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions