Apache Synapse是美国阿帕奇(Apache)基金会的一款轻量级ESB(企业服务总线)。Apache Commons Collections是其中的一个提供了Java集合框架的库。 Apache Synapse中的Apache Commons Collections 3.2.1(commons-collections-3.2.1.jar)及之前的版本中存在注入漏洞。远程攻击者可通过注入特制的序列化对象利用该漏洞执行代码。以下版本受到影响:Apache Synapse 3.0.0版本,2.1.0版
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Synapse | 3.0.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Apache synapse 反序列化 CVE–2017–15708 | https://github.com/HuSoul/CVE-2017-15708 | POC Details |
No public POC found.
Login to generate AI POCNo comments yet