Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data
Vulnerability Description
CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project repo to fix this issue, we will release the new version as soon as possible.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache EventMesh 代码问题漏洞
Vulnerability Description
Apache EventMesh是美国阿帕奇(Apache)基金会的新一代无服务器事件中间件,用于构建分布式事件驱动应用程序。 Apache EventMesh(incubating) V1.7.0至V1.8.0版本存在代码问题漏洞,该漏洞源于rabbitmq-connector plugin模块存在反序列化漏洞。
CVSS Information
N/A
Vulnerability Type
N/A