Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f984-3wx8-grp9

Опубликовано: 05 авг. 2024
Источник: github
Github: Прошло ревью
CVSS4: 9.5
CVSS3: 9

Описание

XXL-RPC Deserialization of Untrusted Data vulnerability

XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.

Пакеты

Наименование

com.xuxueli:xxl-rpc-core

maven
Затронутые версииВерсия исправления

<= 1.7.0

Отсутствует

EPSS

Процентиль: 86%
0.0312
Низкий

9.5 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-502

Связанные уязвимости

CVSS3: 9
nvd
больше 2 лет назад

XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.

EPSS

Процентиль: 86%
0.0312
Низкий

9.5 Critical

CVSS4

9 Critical

CVSS3

Дефекты

CWE-502