PT-2018-17481 · Facebook · Buck
CVE-2018-6331
·
Publicado
2018-12-31
·
Atualizado
2025-05-06
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Buck versions prior to v2018.06.25.01
Description
The issue arises from the Buck parser-cache command, which utilizes Java serialized objects to load and save state. If the state information is maliciously crafted, deserializing it could lead to code execution.
Recommendations
For versions prior to v2018.06.25.01, update to version v2018.06.25.01 or later to resolve the issue.
Correção
Deserialization of Untrusted Data
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Buck