CVE-2022-25767: Deserialization of Untrusted Data
(updated )
All versions of package com.bstek.ureport:ureport2-console is vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
References
Detect and mitigate CVE-2022-25767 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →