cve/2017/CVE-2017-20189.md
2024-06-18 02:51:15 +02:00

806 B

CVE-2017-20189

Description

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.

POC

Reference

Github