Wire
Wire, fast binary POCO serializer
Activity
- Latest release
- 5y ago
- Total releases
- 11
- Cadence
- ~26 days
- Last 12 months
- 0
Details
- First release
- Aug 21, 2015
| Version | Released | |
|---|---|---|
1.0.0
major
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.8.1
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.8.0
minor
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.7.1
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.7.0
minor
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.6
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.5
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.4
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.3
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.2
patch
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev | ||
0.0.1
initial
1 CVE
CVE-2021-29508
GHSA-hpw7-3vq3-mmv6
May 19, 2021
Insecure deserialization in Wire
9.1
/ 10
Critical
Network
Low
None
None
Unchanged
None
High
High
Due to how Wire handles type information in its serialization format, malicious payloads can be passed to a deserializer. e.g. using a surrogate on the sender end, an attacker can pass information about a different type for the receiving end. And by doing so allowing the serializer to create any type on the deserializing end. This is the same issue that exists for .NET BinaryFormatter https://docs.microsoft.com/en-us/visualstudio/code-quality/ca2300?view=vs-2019 This also applies to the fork of Wire, AkkaDotNet/Hyperion. Affected versions
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.7.0
0.7.1
0.8.0
0.8.1
0.8.2
1.0.0
References Updated Feb 17, 2024 · Source: OSV.dev |