Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2020-35490 Vulnerability in maven package com.fasterxml.jackson.core:jackson-databind
CVE-2022-36090 Vulnerability in maven package org.xwiki.platform:xwiki-platform-oldcore
CVE-2021-23342 Vulnerability in npm package docsify
CVE-2020-15366 Vulnerability in maven package org.webjars.bowergithub.ajv-validator:ajv