Description
xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.
Remediation
References
https://github.com/edirc-wong/record/blob/main/deserialization_vulnerability_report.md
Related Vulnerabilities
CVE-2021-22963 Vulnerability in npm package fastify-static
CVE-2020-5497 Vulnerability in maven package org.mitre:openid-connect-server-webapp
CVE-2021-23370 Vulnerability in npm package swiper
CVE-2023-29923 Vulnerability in maven package tech.powerjob:powerjob
CVE-2022-45146 Vulnerability in maven package org.bouncycastle:bc-fips-debug