{"id":"GHSA-gxg6-rc6c-v673","summary":"Improper Input Validation in BeanShell","details":"BeanShell (bsh) before 2.0b6, when included on the classpath by an application that uses Java serialization or XStream, allows remote attackers to execute arbitrary code via crafted serialized data, related to XThis.Handler.","aliases":["CVE-2016-2510"],"modified":"2023-11-08T03:58:24.404260Z","published":"2022-05-13T01:14:25Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2022-07-06T19:57:52Z","nvd_published_at":"2016-04-07T20:59:00Z","cwe_ids":["CWE-20"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2016-2510"},{"type":"WEB","url":"https://github.com/frohoff/ysoserial/pull/13"},{"type":"WEB","url":"https://github.com/beanshell/beanshell/commit/1ccc66bb693d4e46a34a904db8eeff07808d2ced"},{"type":"WEB","url":"https://github.com/beanshell/beanshell/commit/7c68fde2d6fc65e362f20863d868c112a90a9b49"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:1135"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2016:1376"},{"type":"WEB","url":"https://access.redhat.com/errata/RHSA-2019:1545"},{"type":"WEB","url":"https://github.com/beanshell/beanshell/releases/tag/2.0b6"},{"type":"WEB","url":"https://security.gentoo.org/glsa/201607-17"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2020.html"},{"type":"WEB","url":"https://www.rsaconference.com/writable/presentations/file_upload/asd-f03-serial-killer-silently-pwning-your-java-endpoints.pdf"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00056.html"},{"type":"WEB","url":"http://lists.opensuse.org/opensuse-security-announce/2016-03/msg00078.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-0539.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-0540.html"},{"type":"WEB","url":"http://rhn.redhat.com/errata/RHSA-2016-2035.html"},{"type":"WEB","url":"http://www.debian.org/security/2016/dsa-3504"},{"type":"WEB","url":"http://www.ubuntu.com/usn/USN-2923-1"}],"affected":[{"package":{"name":"org.apache-extras.beanshell:bsh","ecosystem":"Maven","purl":"pkg:maven/org.apache-extras.beanshell/bsh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0b6"}]}],"versions":["2.0b5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-gxg6-rc6c-v673/GHSA-gxg6-rc6c-v673.json","last_known_affected_version_range":"\u003c= 2.0b5"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}