Security Advisory

CVE-2020-10721

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-10-22 20:00:48
Last updated 2024-08-04 11:14:14
Assigner redhat
State PUBLISHED

Description

A flaw was found in the fabric8-maven-plugin 4.0.0 and later. When using a wildfly-swarm or thorntail custom configuration, a malicious YAML configuration file on the local machine executing the maven plug-in could allow for deserialization of untrusted data resulting in arbitrary code execution. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.