Description
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
Remediation
References
https://github.com/fengjiachun/Jupiter
https://github.com/fengjiachun/Jupiter/issues/115
https://github.com/welk1n/JNDI-Injection-Exploit/releases/tag/v1.0
Related Vulnerabilities
CVE-2020-7626 Vulnerability in npm package karma-mojo
CVE-2023-27162 Vulnerability in maven package org.openapitools:openapi-generator-project
CVE-2020-28249 Vulnerability in npm package joplin
CVE-2021-32831 Vulnerability in npm package total.js
CVE-2023-48967 Vulnerability in maven package org.noear:solon.serialization.fury