Details
-
Type:
Bug
-
Status: Closed
-
Priority:
Major
-
Resolution: Fixed
-
Affects Version/s: 3.1.4
-
Component/s: Aegis Databinding
-
Labels:None
-
Estimated Complexity:Unknown
Description
Just had a quick look after the topic came up on -users. Aegis Databiding seems to perform unsafe deserialization when serializedWhenUnknown=true. Now sure how common that is (and actually no experience with aegis at all), but if used and enabled that's pretty much direct remote code execution.