PT-2018-17481 · Facebook · Buck

CVE-2018-6331

·

Publicado

2018-12-31

·

Atualizado

2025-05-06

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Buck versions prior to v2018.06.25.01
Description The issue arises from the Buck parser-cache command, which utilizes Java serialized objects to load and save state. If the state information is maliciously crafted, deserializing it could lead to code execution.
Recommendations For versions prior to v2018.06.25.01, update to version v2018.06.25.01 or later to resolve the issue.

Correção

Deserialization of Untrusted Data

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-6331

Produtos afetados

Buck