PT-2025-4026 · Unknown · Y Project Ruoyi

Gsbp

·

Published

2025-01-27

·

Updated

2025-05-13

·

CVE-2025-0734

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions y project RuoYi versions up to 4.8.0
Description A critical issue has been found in the Whitelist component, specifically affecting the getBeanName function. This issue leads to deserialization and can be initiated remotely. The exploit has been publicly disclosed, and the vendor was contacted but did not respond.
Recommendations y project RuoYi versions up to 4.8.0: Update the Whitelist component to prevent deserialization attacks by fixing the getBeanName function.

Exploit

Fix

Deserialization of Untrusted Data

RCE

Weakness Enumeration

Related Identifiers

CVE-2025-0734

Affected Products

Y Project Ruoyi