[MAVEN:GHSA-77H8-5J3H-JCJF] Dromara Hutool Deserialization of Untrusted Data vulnerability

Severity Critical
Affected Packages 1
CVEs 1

Deserialization vulnerability in Dromara Hutool v5.8.11 allows attacker to execute arbitrary code via the XmlUtil.readObjectFromXml parameter.

Package Affected Version
pkg:maven/cn.hutool/hutool-all <= 5.8.11
ID
MAVEN:GHSA-77H8-5J3H-JCJF
Severity
critical
URL
https://github.com/advisories/GHSA-77h8-5j3h-jcjf
Published
2023-01-31T18:30:23
(19 months ago)
Modified
2023-02-16T05:05:53
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/cn.hutool/hutool-all cn.hutool hutool-all <= 5.8.11
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...