← All CVEs

CVE-2022-36944

critical · 9.8

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

9.8
CVSS
10.6%
EPSS (exploit prob.)
96th
EPSS percentile
2022-09-23
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-502

Affected products

VendorProductAffected versions
scala-langscala>= 2.13.0, < 2.13.9
scala-langscala-collection-compat< 2.9.0
fedoraprojectfedora35
fedoraprojectfedora36

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2022-36944