CyberRota Analysis
AI-GeneratedA critical deserialization vulnerability in Apache Fory allows attackers to bypass class-registration checks during Java lambda deserialization, specifically affecting the lambda capture class. This could lead to unauthorized code execution or data manipulation, posing significant risks to applications utilizing affected versions prior to 1.4.0. Organizations using Apache Fory should prioritize upgrading to version 1.4.0 to mitigate this severe threat.
Original NVD Description
Deserialization of untrusted data vulnerability that may allow class-registration checks to be bypassed during Java lambda deserialization. Only lambda capture class is affected This issue affects Apache Fory: from before 1.4.0. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)