PT-2023-19450 · Dromara · Dromara Hutool
S2Etoo
·
Published
2023-01-31
·
Updated
2023-02-07
·
CVE-2023-24162
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Dromara Hutool version 5.8.11
Description
A deserialization issue allows an attacker to execute arbitrary code via the
XmlUtil.readObjectFromXml parameter. This enables the attacker to potentially gain control over the system.Recommendations
For Dromara Hutool version 5.8.11, consider disabling the
XmlUtil.readObjectFromXml parameter as a temporary workaround until a patch is available. Restrict access to this parameter to minimize the risk of exploitation.Exploit
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dromara Hutool