Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache EventMesh: raft Hessian Deserialization Vulnerability allowing remote code execution
Vulnerability Description
CWE-502 Deserialization of Untrusted Data at the eventmesh-meta-raft plugin module in Apache EventMesh master branch without release version on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via hessian deserialization rpc protocol. Users can use the code under the master branch in project repo or version 1.11.0 to fix this issue.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache EventMesh 安全漏洞
Vulnerability Description
Apache EventMesh是美国阿帕奇(Apache)基金会的新一代无服务器事件中间件,用于构建分布式事件驱动应用程序。 Apache EventMesh 1.11.0之前版本存在安全漏洞,该漏洞源于对不受信任的数据进行反序列化,允许攻击者通过hessian反序列化rpc协议发送受控消息和远程代码执行。
CVSS Information
N/A
Vulnerability Type
N/A