← Back to browse · API

CVE-2022-36944

Severity
CRITICAL
CVSS
9.8
EPSS
0.08832
Risk score
42.29
CISA KEV
No
PoC
No
Published
2022-09-23
Modified
2025-05-27
First seen
2026-08-07
Aliases
EUVD-2022-6746, GHSA-8QV5-68G4-248J
Products
n/a:n/a n/a
Sources
euvd EUVD-2022-6746

Description

Scala 2.13.x before 2.13.9 has a Java deserialization chain in its JAR file. On its own, it cannot be exploited. There is only a risk in conjunction with Java object deserialization within an application. In such situations, it allows attackers to erase contents of arbitrary files, make network connections, or possibly run arbitrary code (specifically, Function0 functions) via a gadget chain.

References