CVE-2019-13116

CRITICAL9.8EPSS 2.4%

Mulesoft Mule Unsafe Deserialization

Published: 5/24/2022Modified: 11/8/2023

Description

The MuleSoft Mule runtime engine before 3.8.0 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (4)