CVE-2020-10721
22.10.2020, 20:15
A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.Enginsight
Vendor | Product | Version |
---|---|---|
redhat | fabric8-maven | 4.0.0 ≤ 𝑥 ≤ 4.4.1 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration