PT-2021-19461 · Jfinal · Jfinal
Published
2021-06-24
·
Updated
2022-05-24
·
CVE-2021-31649
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
jfinal versions 4.9.08 and below
Description
The issue is related to a deserialization vulnerability when using redis, which can lead to remote code execution. This vulnerability affects applications that use the jfinal framework.
Recommendations
For versions 4.9.08 and below, consider disabling the deserialization feature when using redis as a temporary workaround until a patch is available. Restrict access to the redis interface to minimize the risk of exploitation.
Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jfinal