Vulnerabilities > CVE-2023-33496 - Deserialization of Untrusted Data vulnerability in Xxl-Rpc Project Xxl-Rpc

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
xxl-rpc-project
CWE-502
critical

Summary

xxl-rpc v1.7.0 was discovered to contain a deserialization vulnerability via the component com.xxl.rpc.core.remoting.net.impl.netty.codec.NettyDecode#decode.

Vulnerable Configurations

Part Description Count
Application
Xxl-Rpc_Project
1

Common Weakness Enumeration (CWE)