Advisories for Maven/Commons-Fileupload/Commons-Fileupload package

2023
2016

Remote Code Execution

There exists a Java Object in this package that can be manipulated in such a way that when it is deserialized, it can write or copy files to disk in arbitrary locations. Furthermore, while the Object can be used alone, this new vector can be integrated with ysoserial to upload and execute binaries in a single deserialization call. This may or may not work depending on an application's implementation of …

2014
2013