Red Hat Drools
Don't miss out!
Thousands of developers use stack.watch to stay informed.Get an email whenever new security vulnerabilities are reported in Red Hat Drools.
By the Year
In 2025 there have been 0 vulnerabilities in Red Hat Drools. Drools did not have any published security vulnerabilities last year.
Year | Vulnerabilities | Average Score |
---|---|---|
2025 | 0 | 0.00 |
2024 | 0 | 0.00 |
2023 | 1 | 8.80 |
2022 | 1 | 9.80 |
2021 | 0 | 0.00 |
2020 | 0 | 0.00 |
2019 | 0 | 0.00 |
2018 | 0 | 0.00 |
It may take a day or so for new Drools vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.
Recent Red Hat Drools Security Vulnerabilities
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data
CVE-2022-1415
8.8 - High
- September 11, 2023
A flaw was found where some utility classes in Drools core did not use proper safeguards when deserializing data. This flaw allows an authenticated attacker to construct malicious serialized objects (usually called gadgets) and achieve code execution on the server.
Marshaling, Unmarshaling
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java
CVE-2021-41411
9.8 - Critical
- June 16, 2022
drools <=7.59.x is affected by an XML External Entity (XXE) vulnerability in KieModuleMarshaller.java. The Validator class is not used correctly, resulting in the XXE injection vulnerability.
XXE
Stay on top of Security Vulnerabilities
Want an email whenever new vulnerabilities are published for Red Hat Drools or by Red Hat? Click the Watch button to subscribe.