Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
Either upgrade to Apache Cayenne 4.2 or a patched version of Java (after 6u211, 7u201, 8u191, and 11.0.1) All versions of Apache Cayenne 4.2 have whitelisting enabled by default for the Hessian deserialization. Later versions of Java also have LDAP mitigation in place. Users can either upgrade Java or Apache Cayenne to avoid the issue. LDAP mitigation is present starting in JDK 6u211, 7u201, 8u191, and 11.0.1 where com.sun.jndi.ldap.object.trustURLCodebase system property is set to false by default to prevent JNDI from loading remote code through LDAP.
No history.

Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T04:07:02.369Z
Reserved: 2022-02-01T00:00:00
Link: CVE-2022-24289

No data.

Status : Modified
Published: 2022-02-11T13:15:08.237
Modified: 2024-11-21T06:50:05.930
Link: CVE-2022-24289

No data.

No data.