Drools: unsafe data deserialization in streamutils
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.1epss 1.0%
exploitation probability
1.0%top 37% of all CVEs
observed exploitation
nono source reports it
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Affected products
Red Hat · Red Hat build of Apache Camel for Spring BootRed Hat · Red Hat build of QuarkusRed Hat · Red Hat Decision Manager 7Red Hat · Red Hat Integration Camel KRed Hat · Red Hat Integration Camel QuarkusRed Hat · Red Hat JBoss Data Grid 7Red Hat · Red Hat JBoss Data Virtualization 6Red Hat · Red Hat JBoss Enterprise Application Platform 6Red Hat · Red Hat JBoss Enterprise Application Platform 7Red Hat · Red Hat JBoss Enterprise Application Platform Expansion PackRed Hat · Red Hat JBoss Fuse 6Red Hat · Red Hat JBoss Fuse 7Red Hat · Red Hat JBoss Fuse Service Works 6Red Hat · Red Hat Process Automation 7Red Hat · RHPAM 7.13.1 async