GHSA-rx62-5cw6-x29q
Dashboard / Vulnerabilities / GHSA-rx62-5cw6-x29q
Summary: Whaleal IceFrog is vulnerable to deserialization
Details: Whaleal IceFrog v1.1.8 component Aviator Template Engine is vulnerable to deserialization of untrusted data. The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-3308, https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal%3Aicefrog/icefrog_1.1.8_RCE.md, https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal:icefrog/icefrog_1.1.8_RCE.md, https://github.com/whaleal/icefrog, https://vuldb.com/?ctiid.231804, https://vuldb.com/?id.231804
Affected packages
Package
Name: com.whaleal.icefrog:icefrog-all
Purl: pkg:maven/com.whaleal.icefrog/icefrog-all
Affected ranges
Type: ECOSYSTEM
Events:
