6.8
CVSSv2

CVE-2020-24164

Published: 11/09/2020 Updated: 15/09/2020
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 606
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

A deserialization flaw is present in Taoensso Nippy prior to 2.14.2. In some circumstances, it is possible for an malicious user to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

taoensso nippy