漏洞标题
在XXL-RPC中远程代码执行
漏洞描述信息
在XXL-RPC中的远程代码执行
CVSS信息
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
漏洞类别
可信数据的反序列化
漏洞标题
Remote code execution in XXL-RPC
漏洞描述信息
XXL-RPC is a high performance, distributed RPC framework. With it, a TCP server can be set up using the Netty framework and the Hessian serialization mechanism. When such a configuration is used, attackers may be able to connect to the server and provide malicious serialized objects that, once deserialized, force it to execute arbitrary code. This can be abused to take control of the machine the server is running by way of remote code execution. This issue has not been fixed.
CVSS信息
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
漏洞类别
可信数据的反序列化
漏洞标题
XXL-RPC 代码问题漏洞
漏洞描述信息
XXL-RPC是一个高性能的分布式 RPC 框架。 XXL-RPC 存在安全漏洞。攻击者利用该漏洞可以远程执行代码。
CVSS信息
N/A
漏洞类别
代码问题