Incomplete List of Disallowed Inputs in SOFA-Hessian
Critical severity
GitHub Reviewed
Published
Mar 6, 2019
to the GitHub Advisory Database
•
Updated Mar 21, 2024
Package
Affected versions
>= 4.0.0, < 4.0.2
< 3.3.6
Patched versions
4.0.2
3.3.6
Description
Published by the National Vulnerability Database
Feb 27, 2019
Published to the GitHub Advisory Database
Mar 6, 2019
Reviewed
Jun 16, 2020
Last updated
Mar 21, 2024
SOFA-Hessian through 4.0.2 allows remote attackers to execute arbitrary commands via a crafted serialized Hessian object because blacklisting of com.caucho.naming.QName and com.sun.org.apache.xpath.internal.objects.XString is mishandled, related to Resin Gadget.
References