Deserialization of Untrusted Data in GitHub repository librenms/librenms prior to 22.10.0.
The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.
Link | Tags |
---|---|
https://huntr.dev/bounties/ed048e8d-87af-440a-a91f-be1e65a40330 | third party advisory permissions required |
https://github.com/librenms/librenms/commit/ae3925b09ad3c5d0f7a9d5a26ae2f2f778834948 | third party advisory patch |