Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Block one more gadget type (duplicate report) #2641

Closed
threedr3am opened this issue Mar 3, 2020 · 1 comment
Closed

Block one more gadget type (duplicate report) #2641

threedr3am opened this issue Mar 3, 2020 · 1 comment

Comments

@threedr3am
Copy link

Hello, buddy. It's me again. I recently found a JRE dependent gadget that can be used for SSRF(Server Side Request Forgery) when deserializing.
I have sent an email to [email protected] for details of the vulnerability

@cowtowncoder cowtowncoder changed the title A new SSRF gadget was found Block one more gadget type (javax.swing, CVE-to-be-allocated) Mar 4, 2020
@cowtowncoder
Copy link
Member

Re-filed as #2642.

@cowtowncoder cowtowncoder added the CVE Issues related to public CVEs (security vuln reports) label Jul 16, 2020
@cowtowncoder cowtowncoder changed the title Block one more gadget type (javax.swing, CVE-to-be-allocated) Block one more gadget type (duplicate report) Dec 2, 2020
@cowtowncoder cowtowncoder removed the CVE Issues related to public CVEs (security vuln reports) label Dec 2, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants