QID 980960
QID 980960: Java (maven) Security Update for com.alipay.sofa:hessian (GHSA-pfwp-8pq4-g7pv)
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-pfwp-8pq4-g7pv for updates pertaining to this vulnerability.
Vendor References
- GHSA-pfwp-8pq4-g7pv -
github.com/advisories/GHSA-pfwp-8pq4-g7pv
CVEs related to QID 980960
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-pfwp-8pq4-g7pv | com.alipay.sofa:hessian |
|