Description
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
Remediation
References
https://github.com/edirc-wong/record/blob/main/deserialization_vulnerability_report.md
Related Vulnerabilities
CVE-2022-22984 Vulnerability in npm package snyk-python-plugin
CVE-2018-3717 Vulnerability in npm package anywhere
CVE-2019-13127 Vulnerability in maven package org.webjars.npm:mxgraph
CVE-2016-0711 Vulnerability in maven package org.apache.portals.jetspeed-2:j2-admin
CVE-2018-1335 Vulnerability in maven package org.apache.tika:tika-server