Remote Code Execution (RCE) Affecting org.scala-lang:scala-library package, versions [2.13.0,2.13.9)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.Test your applications
- Snyk ID SNYK-JAVA-ORGSCALALANG-3032987
- published 25 Sep 2022
- disclosed 25 Sep 2022
- credit Marc Bohler
How to fix?
org.scala-lang:scala-library to version 2.13.9 or higher.
Affected versions of this package are vulnerable to Remote Code Execution (RCE) due to a vulnerable Java deserialization chain when used in conjunction with
LazyList object deserialization, which may allow execution of an arbitrary