CVE-2024-28212: Critical severity ngrinder vulnerability
Published Mar 7, 2024
·Updated
nGrinder before 3.5.9 uses old version of SnakeYAML, which could allow remote attacker to execute arbitrary code via unsafe deserialization.
Affected Software
2 affected components
nGrinder nGrinder<3.5.9
NAVER Ngrinder<3.5.9
Event History
Mar 7, 2024
CVE Published
via MITRE·04:49 AM
Data Sourced
via MITRE·04:49 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-28212?
CVE-2024-28212 is considered a critical vulnerability due to the potential for arbitrary code execution through unsafe deserialization.
2
How do I fix CVE-2024-28212?
To fix CVE-2024-28212, upgrade nGrinder to version 3.5.9 or later.
3
What software is affected by CVE-2024-28212?
CVE-2024-28212 affects nGrinder versions prior to 3.5.9.
4
Can CVE-2024-28212 be exploited remotely?
Yes, CVE-2024-28212 can be exploited remotely by an attacker due to the nature of unsafe deserialization.
5
What is the cause of CVE-2024-28212?
CVE-2024-28212 is caused by nGrinder using an outdated version of SnakeYAML, which is vulnerable to unsafe deserialization.