Buck parser-cache command loads/saves state using Java serialized object. If the state information is maliciously crafted, deserializing it could lead to code execution. This issue affects Buck versions prior to v2018.06.25.01.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 06 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | cvssV3_1 
 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: facebook
Published:
Updated: 2025-05-06T15:46:07.371Z
Reserved: 2018-01-26T00:00:00.000Z
Link: CVE-2018-6331
 Vulnrichment
                        Vulnrichment
                    Updated: 2024-08-05T06:01:48.362Z
 NVD
                        NVD
                    Status : Modified
Published: 2018-12-31T23:29:00.237
Modified: 2025-05-06T16:15:20.427
Link: CVE-2018-6331
 Redhat
                        Redhat
                    No data.