PT-2025-4026 · Unknown · Y Project Ruoyi
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
y project RuoYi versions up to 4.8.0
Description
A critical issue has been found in the Whitelist component, specifically affecting the
getBeanName function. This issue leads to deserialization and can be initiated remotely. The exploit has been publicly disclosed, and the vendor was contacted but did not respond.Recommendations
y project RuoYi versions up to 4.8.0: Update the Whitelist component to prevent deserialization attacks by fixing the
getBeanName function.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Y Project Ruoyi