GHSA-9378-f4v7-jgm4
CRITICALCVE-2021-41616Apache DB DdlUtils 1.0 included a BinaryObjectsHelper that was intended for use when migrating database data with a SQL data type of BINARY, VARBINARY, LONGVARBINARY, or BLOB between databases using the ddlutils features. The BinaryObjectsHelper class was insecure and used ObjectInputStream.readObject without validating that the input data was safe to deserialize. Please note that DdlUtils is no l
- Affected
- <= 1.0
- Fixed in
- not stated
- Weakness
- CWE-502
- Published
- 2021-10-04
- Source
- github