CVE-2022-36944
Last modified
CVE-2022-36944 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. EPSS estimates a 8.19% chance of exploitation in the next 30 days.
Description
Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Scala-Lang | Scala | >= 2.13.0, < 2.13.9 |
| Scala-Lang | Scala-Collection-Compat | < 2.9.0 |
| Fedoraproject | Fedora | 35 |
| Fedoraproject | Fedora | 36 |
References
- https://github.com/scala/scala-collection-compat/releases/tag/v2.9.0Release Notes, Third Party Advisory
- https://github.com/scala/scala/pull/10118Exploit, Patch, Third Party Advisory
- https://www.scala-lang.org/download/Vendor Advisory
- https://github.com/scala/scala-collection-compat/releases/tag/v2.9.0Release Notes, Third Party Advisory
- https://github.com/scala/scala/pull/10118Exploit, Patch, Third Party Advisory
- https://www.scala-lang.org/download/Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-36944?
How severe is CVE-2022-36944?
How do I fix CVE-2022-36944?
Are you affected by CVE-2022-36944?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
