Scala-lang Scala 2.13.1

CPE Details

Scala-lang Scala 2.13.1
2.13.1
2019-12-09
12h39 +00:00
2019-12-09
12h39 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:scala-lang:scala:2.13.1:*:*:*:*:*:*:*

Informations

Vendor

scala-lang

Product

scala

Version

2.13.1

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2022-36944 2022-09-22 22h00 +00:00 Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.
9.8
Critical