nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
History

Wed, 07 May 2025 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Naver
Naver ngrinder
CPEs cpe:2.3:a:naver:ngrinder:*:*:*:*:*:*:*:*
Vendors & Products Naver
Naver ngrinder

Thu, 22 Aug 2024 21:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: naver

Published: 2024-03-07T04:49:47.237Z

Updated: 2024-08-22T20:01:34.318Z

Reserved: 2024-03-07T02:38:58.221Z

Link: CVE-2024-28213

cve-icon Vulnrichment

Updated: 2024-08-02T00:48:49.537Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-07T05:15:54.710

Modified: 2025-05-07T15:30:21.283

Link: CVE-2024-28213

cve-icon Redhat

No data.