In Corda before 4.1, the meaning of serialized data can be modified via an attacker-controlled CustomSerializer.
                
            References
                    | Link | Resource | 
|---|---|
| https://docs.r3.com/en/platform/corda/4.1/open-source/release-notes.html | Release Notes Vendor Advisory | 
Configurations
                    Information
                Published : 2022-02-14 13:15
Updated : 2022-02-23 08:13
NVD link : CVE-2019-25057
Mitre link : CVE-2019-25057
JSON object : View
CWE
                Products Affected
                r3
- corda
 


