← Back to browse · API

CVE-2018-6331

Severity
CRITICAL
CVSS
9.8
EPSS
0.02452
Risk score
40.06
CISA KEV
No
PoC
No
Published
2018-12-31
Modified
2025-05-06
First seen
2026-08-07
Aliases
EUVD-2018-18092, GHSA-GWVW-V6HG-775R
Products
Facebook:Buck unspecified ≤v2018.06.25.01, Facebook:Buck v2018.06.25.01
Sources
euvd EUVD-2018-18092

Description

Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.

References