XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.
Metrics
Affected Vendors & Products
References
History
Thu, 29 Aug 2024 20:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
MITRE
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-10-18T21:56:55.614Z
Updated: 2024-08-29T17:09:23.119Z
Reserved: 2023-10-04T16:02:46.330Z
Link: CVE-2023-45146
Vulnrichment
Updated: 2024-08-19T07:48:07.804Z
NVD
Status : Modified
Published: 2023-10-18T22:15:09.323
Modified: 2024-11-21T08:26:26.510
Link: CVE-2023-45146
Redhat
No data.