PT-2025-4026 · Unknown · Y Project Ruoyi

·

CVE-2025-0734

·

Published

2025-01-27

·

Updated

2025-05-13

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions y project RuoYi versions up to 4.8.0
Description A critical issue has been found in the Whitelist component, specifically affecting the getBeanName function. This issue leads to deserialization and can be initiated remotely. The exploit has been publicly disclosed, and the vendor was contacted but did not respond.
Recommendations y project RuoYi versions up to 4.8.0: Update the Whitelist component to prevent deserialization attacks by fixing the getBeanName function.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-0734

Affected Products

Y Project Ruoyi