CVE-2022-36944 Scala 213x before 2139 has a Java deserialization chain in its JAR file On its own, it cannot be exploited There is only a risk in conjunction with Java object deserialization within an application In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0