Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Apache Fory, Apache Fory: Out-of-Bounds Read via sun.misc.Unsafe in zero-copy java deserialization
Vulnerability Description
Out-of-bounds read via sun.misc.Unsafe in Apache Fory. When out-of-band zero-copy deserialization is used, readAlignedVarUint() can read beyond the bounds of the underlying buffer. Out-of-band zero-copy deserialization is an opt-in feature; applications that do not use it are not affected. This issue affects Apache Fory (formerly Apache Fury): from 0.5.0 before 1.4.0. Versions before 0.11.0 were published under the Maven coordinates org.apache.fury:fury-core. Users are recommended to upgrade to version 1.4.0, which fixes the issue.
CVSS Information
N/A
Vulnerability Type
跨界内存读
Vulnerability Title
Apache Fory 缓冲区错误漏洞
Vulnerability Description
Apache fory是美国Apache基金会开源的一款Web应用框架。 Apache Fory 0.5.0版本至1.4.0之前版本存在缓冲区错误漏洞,该漏洞源于使用带外零拷贝反序列化时,readAlignedVarUint()函数中的越界读取问题,可能导致敏感信息泄露。
CVSS Information
N/A
Vulnerability Type
N/A