Remote Code Execution in Halibut
Critical severity
GitHub Reviewed
Published
Sep 23, 2021
to the GitHub Advisory Database
•
Updated Feb 1, 2023
Description
Published by the National Vulnerability Database
Sep 22, 2021
Reviewed
Sep 23, 2021
Published to the GitHub Advisory Database
Sep 23, 2021
Last updated
Feb 1, 2023
In Halibut versions prior to 4.4.7 there is a deserialisation vulnerability that could allow remote code execution on systems that already trust each other based on certificate verification.
References