A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: redhat

Published: 2023-09-11T20:20:23.745Z

Updated: 2024-05-03T15:32:23.354Z

Reserved: 2022-04-20T12:43:39.822Z


Link: CVE-2022-1415

JSON object: View

cve-icon NVD Information

Status : Modified

Published: 2023-09-11T21:15:41.483

Modified: 2024-05-03T16:15:07.767


Link: CVE-2022-1415

JSON object: View

cve-icon Redhat Information

No data.

CWE