CVE-2017-20189
22.01.2024, 06:15
In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.Enginsight
| Vendor | Product | Version |
|---|---|---|
| clojure | clojure | 𝑥 < 1.9.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Common Weakness Enumeration
References