CVE-2023-3308

MEDIUM

whaleal IceFrog 1.1.8 - Deserialization

Title source: llm

Description

A vulnerability classified as problematic has been found in whaleal IceFrog 1.1.8. Affected is an unknown function of the component Aviator Template Engine. The manipulation leads to deserialization. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-231804.

Scores

CVSS v3 5.5
EPSS 0.0012
EPSS Percentile 30.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Classification

CWE
CWE-502
Status published

Affected Products (2)

whaleal/icefrog
com.whaleal.icefrog/icefrog-all Maven

Timeline

Published Jun 18, 2023
Tracked Since Feb 18, 2026