Code Injection in cryo
Critical severity
GitHub Reviewed
Published
Aug 21, 2018
to the GitHub Advisory Database
•
Updated Sep 12, 2023
Description
Published to the GitHub Advisory Database
Aug 21, 2018
Reviewed
Jun 16, 2020
Last updated
Sep 12, 2023
All versions of
cryo
are vulnerable to code injection due to an Insecure implementation of deserialization.Proof of concept
Recommendation
No fix is currently available. Consider using an alternative module until a fix is made available.
References