Description
Apache Olingo versions 4.0.0 to 4.6.0 provide the AbstractService class, which is public API, uses ObjectInputStream and doesn't check classes being deserialized. If an attacker can feed malicious metadata to the class, then it may result in running attacker's code in the worse case.
Remediation
References
https://mail-archives.apache.org/mod_mbox/olingo-user/201912.mbox/%3CCAGSZ4d4vbSYaVh3aUWAvcVHK2qcFxxCZd3WAx3xbwZXskPX8nw%40mail.gmail.com%3E
Related Vulnerabilities
CVE-2023-32314 Vulnerability in maven package org.webjars.npm:vm2
CVE-2020-1952 Vulnerability in maven package org.apache.iotdb:iotdb-server
CVE-2021-36737 Vulnerability in maven package org.apache.portals.pluto.demo:v3-demo-portlet
CVE-2021-36163 Vulnerability in maven package org.apache.dubbo:dubbo-serialization
CVE-2021-45046 Vulnerability in maven package org.apache.logging.log4j:log4j-core