CVE-2023-34617

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jun 14, 2023
Updated: Jun 23, 2023
CWE ID 787

Summary

CVE-2023-34617 is a newly disclosed vulnerability affecting genson, a popular Java serialization library, up to version 1.6. Attackers can exploit this issue by providing crafted objects with cyclic dependencies, leading to unintended consequences, including a denial of service. The exact nature of these impacts remains undefined, but the vulnerability poses a significant risk to systems utilizing the affected library. Users are strongly encouraged to update to the latest version of genson to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share