GHSA-q8cm-3v62-jj79
CRITICALCVE-2023-37895Java object deserialization issue in Jackrabbit webapp/standalone on all platforms allows attacker to remotely execute code via RMIVersions up to (including) 2.20.10 (stable branch) and 2.21.17 (unstable branch) use the component "commons-beanutils", which contains a class that can be used for remote code execution over RMI.
- Affected
- >= 2.21.0, < 2.21.18, >= 1.0.0, < 2.20.11
- Fixed in
- 2.21.18
- Weakness
- CWE-502
- Published
- 2023-07-25
- Source
- github