[
  {"cve_id":"CVE-2016-4000","description":"Jython before 2.7.1rc1 allows attackers to execute arbitrary code via a crafted serialized PyFunction object.","exploit_maturity":"No public exploit","published":"2017-07-06","resolved":"MITIGATED-BY-RASP","severity":"Critical"},
  {"cve_id":"CVE-2013-2027","description":"Jython 2.2.1 uses the current umask to set the privileges of the class cache files, which allows local users to bypass intended access restrictions via unspecified vectors.","exploit_maturity":"No public exploit","published":"2015-02-13","resolved":"OUT-OF-SCOPE","severity":"Medium"}
]
