Description
XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.
Published: 2023-10-18
Score: 9.1 Critical
EPSS: 3.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2024-2573 XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.
Github GHSA Github GHSA GHSA-f984-3wx8-grp9 XXL-RPC Deserialization of Untrusted Data vulnerability
History

Thu, 29 Aug 2024 20:30:00 +0000

Type Values Removed Values Added
References

Subscriptions

Xxl-rpc Project Xxl-rpc
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-29T17:09:23.119Z

Reserved: 2023-10-04T16:02:46.330Z

Link: CVE-2023-45146

cve-icon Vulnrichment

Updated: 2024-08-19T07:48:07.804Z

cve-icon NVD

Status : Modified

Published: 2023-10-18T22:15:09.323

Modified: 2024-11-21T08:26:26.510

Link: CVE-2023-45146

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses