Description
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
Remediation
References
https://github.com/edirc-wong/record/blob/main/deserialization_vulnerability_report.md
Related Vulnerabilities
CVE-2019-6286 Vulnerability in npm package node-sass
CVE-2020-7656 Vulnerability in maven package org.fujion.webjars:jquery
CVE-2022-25894 Vulnerability in maven package com.bstek.uflo:uflo-core
CVE-2016-0710 Vulnerability in maven package org.apache.portals.jetspeed-2:jetspeed-security
CVE-2018-12540 Vulnerability in maven package io.vertx:vertx-web