CVE-2020-17532: Deserialization of Untrusted Data
When handler-router component is enabled in servicecomb-java-chassis, authenticated user may inject some data and cause arbitrary code execution. The problem happens in versions between ~ and fixed in Apache ServiceComb-Java-Chassis.
References
Detect and mitigate CVE-2020-17532 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →