CVE-2021-36483
CVE-2021-36483
DevExpress.XtraReports.UI through v21.1 allows attackers to execute arbitrary code via insecure deserialization.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
https://gist.github.com/tree-chtsec/27013ed6cb297b24e44f6359439b678ehttps://supportcenter.devexpress.com/ticket/details/t1031535/reporting-unsafe-data-type-deserializationhttps://supportcenter.devexpress.com/ticket/details/t708194/net-web-controls-unsafe-data-type-deserializationhttps://supportcenter.devexpress.com/ticket/details/t714296/net-desktop-controls-unsafe-data-type-deserializationhttps://www.chtsecurity.com/news/a01d1bc6-19c8-4187-b343-6bc685efe64fhttps://www.zerodayinitiative.com/advisories/ZDI-22-341/