{"id":"GHSA-rx62-5cw6-x29q","summary":"Whaleal IceFrog is vulnerable to deserialization ","details":"Whaleal IceFrog v1.1.8 component Aviator Template Engine is vulnerable to deserialization of untrusted data. The application deserializes untrusted data without sufficiently verifying that the resulting data will be valid.","aliases":["CVE-2023-3308"],"modified":"2024-03-01T14:47:10.755017Z","published":"2023-06-18T09:30:17Z","database_specific":{"cwe_ids":["CWE-502"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2023-06-19T22:46:24Z","nvd_published_at":"2023-06-18T09:15:09Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-3308"},{"type":"WEB","url":"https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal%3Aicefrog/icefrog_1.1.8_RCE.md"},{"type":"WEB","url":"https://github.com/NanKeXXX/selfVuln_poc/blob/main/whaleal:icefrog/icefrog_1.1.8_RCE.md"},{"type":"PACKAGE","url":"https://github.com/whaleal/icefrog"},{"type":"WEB","url":"https://vuldb.com/?ctiid.231804"},{"type":"WEB","url":"https://vuldb.com/?id.231804"}],"affected":[{"package":{"name":"com.whaleal.icefrog:icefrog-all","ecosystem":"Maven","purl":"pkg:maven/com.whaleal.icefrog/icefrog-all"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.1.8"}]}],"versions":["1.0.0","1.0.1","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.1.7","1.1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-rx62-5cw6-x29q/GHSA-rx62-5cw6-x29q.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"}]}