← Back to CVE List

CVE-2020-24164

Published: 2020-09-11T06:15Z
Last Modified: 2024-11-21T05:14Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt