Description
A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.
Remediation
References
https://hackerone.com/reports/350418
Related Vulnerabilities
CVE-2023-33202 Vulnerability in maven package org.bouncycastle:bc-fips
CVE-2021-25913 Vulnerability in npm package set-or-get
CVE-2022-43412 Vulnerability in maven package org.jenkins-ci.plugins:generic-webhook-trigger
CVE-2021-23337 Vulnerability in maven package org.webjars.bowergithub.lodash:lodash
CVE-2022-22984 Vulnerability in npm package @snyk/snyk-cocoapods-plugin