nGrinder before 3.5.9 allows to accept serialized Java objects from unauthenticated users, which could allow remote attacker to execute arbitrary code via unsafe Java objects deserialization.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://cve.naver.com/detail/cve-2024-28213.html | Vendor Advisory |
https://cve.naver.com/detail/cve-2024-28213.html | Vendor Advisory |
Configurations
History
07 May 2025, 15:30
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-502 | |
References | () https://cve.naver.com/detail/cve-2024-28213.html - Vendor Advisory | |
CPE | cpe:2.3:a:naver:ngrinder:*:*:*:*:*:*:*:* | |
First Time |
Naver
Naver ngrinder |
07 Mar 2024, 05:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-03-07 05:15
Updated : 2025-05-07 15:30
NVD link : CVE-2024-28213
Mitre link : CVE-2024-28213
JSON object : View
Products Affected
naver
- ngrinder
CWE
CWE-502
Deserialization of Untrusted Data