Логотип exploitDog
bind:CVE-2024-56180
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-56180

Количество 3

Количество 3

ubuntu логотип

CVE-2024-56180

12 месяцев назад

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2024-56180

12 месяцев назад

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.

CVSS3: 9.8
EPSS: Низкий
github логотип

GHSA-ffvr-gmp3-xx43

12 месяцев назад

Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

CVSS3: 9.8
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
nvd логотип
CVE-2024-56180

CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.

CVSS3: 9.8
1%
Низкий
12 месяцев назад
github логотип
GHSA-ffvr-gmp3-xx43

Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution

CVSS3: 9.8
1%
Низкий
12 месяцев назад

Уязвимостей на страницу