The MuleSoft Mule Community Edition runtime engine before 3.8 allows remote attackers to execute arbitrary code because of Java Deserialization, related to Apache Commons Collections
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://docs.mulesoft.com/release-notes/mule-runtime/mule-3.8.0-release-notes | release notes |
https://threat.tevora.com/mulesoft-3-8-unauthenticated-rce/ | third party advisory exploit |