CVE-2020-24164

HIGH

Taoensso Nippy <2.14.2 - Deserialization

Title source: llm

Description

A deserialization flaw is present in Taoensso Nippy before 2.14.2. In some circumstances, it is possible for an attacker to create a malicious payload that, when deserialized, will allow arbitrary code to be executed. This occurs because there is automatic use of the Java Serializable interface.

Scores

CVSS v3 7.8
EPSS 0.0014
EPSS Percentile 34.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (2)

taoensso/nippy < 2.14.2
com.taoensso/nippy < 2.14.2Maven

Timeline

Published Sep 11, 2020
Tracked Since Feb 18, 2026