Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Spring | Spring For Apache Kafka | 2.8.x ~ 2.9.11 | - |
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | POC for Spring Kafka Deserialization Vulnerability CVE-2023-34040 | https://github.com/Contrast-Security-OSS/Spring-Kafka-POC-CVE-2023-34040 | POC Details |
| 2 | Spring-Kafka-Deserialization-Remote-Code-Execution | https://github.com/pyn3rd/CVE-2023-34040 | POC Details |
| 3 | In Spring for Apache Kafka 3.0.9 and earlier and versions 2.9.10 and earlier, a possible deserialization attack vector existed, but only if unusual configuration was applied. An attacker would have to construct a malicious serialized object in one of the deserialization exception record headers. Cre: NVD | https://github.com/buiduchoang24/CVE-2023-34040 | POC Details |
| 4 | None | https://github.com/huyennhat-dev/cve-2023-34040 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet