Scala-Lang scala-collection-compat 2.3.0

CPE Details

Scala-Lang scala-collection-compat 2.3.0
2.3.0
2023-07-26
13h44 +00:00
2023-07-26
13h51 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:scala-lang:scala-collection-compat:2.3.0:*:*:*:*:*:*:*

Informations

Vendor

scala-lang

Product

scala-collection-compat

Version

2.3.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2022-36944 2022-09-22 22h00 +00:00 Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.
9.8
Critique