CVE-2017-7536: Use of Externally-Controlled Input to Select Classes or Code (Unsafe Reflection)
(updated )
An attacker may be able to validate an invalid instance and access the private member value via ConstraintViolation#getInvalidValue()
.
References
Detect and mitigate CVE-2017-7536 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →