xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
References
Link | Resource |
---|---|
https://github.com/edirc-wong/record/blob/main/deserialization_vulnerability_report.md | Exploit |
Configurations
History
No history.
Information
Published : 2023-06-07 21:15
Updated : 2023-06-15 16:35
NVD link : CVE-2023-33496
Mitre link : CVE-2023-33496
CVE.ORG link : CVE-2023-33496
JSON object : View
Products Affected
xxl-rpc_project
- xxl-rpc
CWE
CWE-502
Deserialization of Untrusted Data