peter bassill · operator
$ cve CVE-2022-36944 JSON

CVE-2022-36944

9.8
CRITICAL · CVSS 3.1 · EPSS 10.6% (pctl 96)

Patch early

EPSS 10.6% — above the 10% action threshold.

Description

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS10.62% — more likely to be exploited than 96% of all CVEs
WeaknessCWE-502
On CISA KEVno
Public exploitnone known
Published2022-09-23
Last modified2026-06-17

Affected (3)

VendorProduct
fedoraprojectfedora
scala-langscala
scala-langscala-collection-compat

References

→ the Explorer  ·  watch your stack  ·  NVD