GHSA-wq4c-57mh-5f7g
CRITICALCVE-2025-64408Apache Causeway faces Java deserialization vulnerabilities that allow remote code execution (RCE) through user-controllable URL parameters. These vulnerabilities affect all applications using Causeway's ViewModel functionality and can be exploited by authenticated attackers to execute arbitrary code with application privileges.
- Affected
- < 3.5.0
- Fixed in
- 3.5.0
- Weakness
- CWE-502
- Published
- 2025-11-19
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference