Description
XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-2573 | XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed. |
Github GHSA |
GHSA-f984-3wx8-grp9 | XXL-RPC Deserialization of Untrusted Data vulnerability |
References
History
Thu, 29 Aug 2024 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2024-08-29T17:09:23.119Z
Reserved: 2023-10-04T16:02:46.330Z
Link: CVE-2023-45146
Updated: 2024-08-19T07:48:07.804Z
Status : Modified
Published: 2023-10-18T22:15:09.323
Modified: 2024-11-21T08:26:26.510
Link: CVE-2023-45146
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA