CVE-2020-24164
HIGHTaoensso Nippy <2.14.2 - Deserialization
Title source: llmDescription
A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.
Scores
CVSS v3
7.8
EPSS
0.0014
EPSS Percentile
34.0%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (2)
taoensso/nippy
< 2.14.2
com.taoensso/nippy
< 2.14.2Maven
Timeline
Published
Sep 11, 2020
Tracked Since
Feb 18, 2026