CVE-2018-3784

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
17/08/2018
Last modified:
18/09/2020

Description

A code injection in cryo 0.0.6 allows an attacker to arbitrarily execute code due to insecure implementation of deserialization.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:cryo_project:cryo:0.0.6:*:*:*:*:node.js:*:*


References to Advisories, Solutions, and Tools