漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
Apache Axis2/Java: deserialization of untrusted Data
Vulnerability Description
Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat (only when Tribes clustering is enabled, which is off by default) allows an unauthenticated remote attacker with network access to the clustering port to execute arbitrary code via a crafted serialized Java object delivered to the cluster channel and deserialized in org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are recommended to upgrade to version 2.0.1, which fixes this issue by removing the clustering feature entirely.
CVSS Information
N/A
Vulnerability Type
可信数据的反序列化
Vulnerability Title
Apache Axis2/Java 反序列化注入漏洞
Vulnerability Description
Apache Axis2/Java是美国Apache基金会的一个Web服务中间件。 Apache Software Foundation Apache Axis2/Java 2.0.0版本及之前版本存在反序列化注入漏洞,该漏洞源于Tribes-based clustering组件中的反序列化不受信任的数据问题,可能导致未经身份验证的远程攻击者通过网络访问集群端口,利用特制序列化Java对象执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A