CVE-2017-20189

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
22/01/2024
Last modified:
03/11/2025

Description

In Clojure before 1.9.0, classes can be used to construct a serialized object that executes arbitrary code upon deserialization. This is relevant if a server deserializes untrusted objects.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:clojure:clojure:*:*:*:*:*:*:*:* 1.9.0 (excluding)