Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.
{ "urgency": "not yet assigned" }