Solon vulnerable to deserialization of untrusted data
Critical severity
GitHub Reviewed
Published
Jun 19, 2023
to the GitHub Advisory Database
•
Updated Mar 7, 2024
Description
Published by the National Vulnerability Database
Jun 19, 2023
Published to the GitHub Advisory Database
Jun 19, 2023
Reviewed
Jun 20, 2023
Last updated
Mar 7, 2024
A bypass in the component sofa-hessian of Solon before v2.3.3 allows attackers to execute arbitrary code via providing crafted payload.
References