Advisories for Maven/Org.drools/Drools package

2023

Deserialization of Untrusted Data

A flaw was found where some utility classes in Drools core does not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.

2022