QID 996847
Date Published: 2024-01-24
QID 996847: Java (Maven) Security Update for com.alipay.sofa:rpc-sofa-boot-starter (GHSA-7q8p-9953-pxvr)
Impact SOFARPC defaults to using the SOFA Hessian protocol to deserialize received data, while the SOFA Hessian protocol uses a blacklist mechanism to restrict deserialization of potentially dangerous classes for security protection. But there is a gadget chain that can bypass the SOFA Hessian blacklist protection mechanism, and this gadget chain only relies on JDK and does not rely on any third-party components.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7q8p-9953-pxvr for updates and patch information.
Vendor References
- GHSA-7q8p-9953-pxvr -
github.com/advisories/GHSA-7q8p-9953-pxvr
CVEs related to QID 996847
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7q8p-9953-pxvr | com.alipay.sofa:rpc-sofa-boot-starter |
|