CVE-2020-9493

CVE-2020-9493: Java deserialization in Chainsaw

Vendor Apache Software Foundation
Product Apache Chainsaw
Weakness CWE-502 · Unsafe deserialization
Published June 16, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

Description

A deserialization flaw was found in Apache Chainsaw versions prior to 2.1.0 which could lead to malicious code execution.

Key dates

Disclosure timeline

June 16, 2021 CVE published
August 4, 2024 Record updated