Skip to main content
Loading…
    CVE-2023-38647 — An attacker can use SnakeYAML to deserialize java.net.URLClassLoader and make it load a JAR from a specified URL, and then deserialize javax.script.ScriptEngineManager to load code using that ClassLoa — CVE Database · The Intelligence Room