Red Hat Bugzilla – Bug 1420339
CVE-2016-6199 gradle: Unsafe data deserialization in the ObjectSocketWrapper class
Last modified: 2018-08-18 07:26:12 EDT
A vulnerability was found in gradle. ObjectSocketWrapper.java allows remote attackers to execute arbitrary code via a crafted serialized object. References: https://philwantsfish.github.io/security/java-deserialization-github https://discuss.gradle.org/t/a-security-issue-about-gradle-rce/17726
Created gradle tracking bugs for this issue: Affects: fedora-24 [bug 1420347] Affects: epel-6 [bug 1420348]