Deserialization of Untrusted Data Affecting xmvn-mojo package, versions <4.0.0-150200.3.7.8


Severity

Recommended
high

Based on SUSE Linux Enterprise Server security rating.

Threat Intelligence

EPSS
1.64% (88th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Deserialization of Untrusted Data vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-SLES152-XMVNMOJO-5500256
  • published9 May 2023
  • disclosed4 May 2023

Introduced: 4 May 2023

CVE-2021-42550  (opens in a new tab)
CWE-502  (opens in a new tab)

How to fix?

Upgrade SLES:15.2 xmvn-mojo to version 4.0.0-150200.3.7.8 or higher.

NVD Description

Note: Versions mentioned in the description apply only to the upstream xmvn-mojo package and not the xmvn-mojo package as distributed by SLES. See How to fix? for SLES:15.2 relevant fixed versions and status.

In logback version 1.2.7 and prior versions, an attacker with the required privileges to edit configurations files could craft a malicious configuration allowing to execute arbitrary code loaded from LDAP servers.

CVSS Scores

version 3.1